CVE-2010-3273
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to…
Does this matter?
Lower severity and a low EPSS score (3.33%). Track it; it rarely justifies an emergency change on its own.
Description
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.33% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70869
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65348
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70869
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65348
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.