ManageEngine Vulnerabilities and Affected Products
Vulnerabilities associated with ADSelfService Plus.
Products
Clear product- ADAudit Plus35 vulnerabilities
- adaudit_plus25 vulnerabilities
- Applications Manager8 vulnerabilities
- Exchange Reporter Plus8 vulnerabilities
- ADSelfService Plus5 vulnerabilities
- OpManager5 vulnerabilities
- Endpoint Central4 vulnerabilities
- ServiceDesk Plus MSP4 vulnerabilities
- Desktop Central3 vulnerabilities
- exchange_reporter_plus3 vulnerabilities
- PAM3603 vulnerabilities
- ServiceDesk Plus3 vulnerabilities
- SupportCenter Plus3 vulnerabilities
- ADManager Plus2 vulnerabilities
- Analytics Plus2 vulnerabilities
- Asset Explorer2 vulnerabilities
- DDI Central2 vulnerabilities
- servicedesk2 vulnerabilities
- Access Manager Plus1 vulnerability
- desktop_central1 vulnerability
- OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition1 vulnerability
- OpManager, Remote Monitoring and Management1 vulnerability
- Password Manager Pro1 vulnerability
- password_manager_pro1 vulnerability
- Service Desk Plus1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3833HIGH | SQL InjectionZohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. CWE-89May 14, 2025 | CVSS8.1v3.1 | EPSS38.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1723HIGH | Account takeoverZohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. CWE-287Mar 3, 2025 | CVSS8.1v3.1 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-27310MEDIUM | DOS VulnerabilityZoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input. CWE-90May 27, 2024 | CVSS5.3v3.1 | EPSS2.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0252HIGH | Remote code executionManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability. CWE-94Jan 11, 2024 | CVSS8.8v3.1 | EPSS7.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35719MEDIUM | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass VulnerabilityManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Password Reset Portal used by the GINA client. The issue results from the lack of proper authentication of data received via HTTP.… CWE-345Sep 6, 2023 | CVSS6.8v3.1 | EPSS26.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |