CVE-2022-36412

CRITICAL

Zoho ManageEngine SupportCenter Plus <11023 - Auth Bypass

Title source: llm
STIX 2.1

Description

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0150
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
zohocorp/manageengine_supportcenter_plus 11.0 11020 (3 CPE variants)
Published Jul 26, 2022
Tracked Since Feb 18, 2026