Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_adselfservice_plus | Zohocorp | 4.5-4510 (including) | 4.5-4510 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4511 (including) | 4.5-4511 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4520 (including) | 4.5-4520 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4522 (including) | 4.5-4522 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4531 (including) | 4.5-4531 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4540 (including) | 4.5-4540 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4543 (including) | 4.5-4543 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4544 (including) | 4.5-4544 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4550 (including) | 4.5-4550 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4560 (including) | 4.5-4560 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4570 (including) | 4.5-4570 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4571 (including) | 4.5-4571 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4572 (including) | 4.5-4572 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4580 (including) | 4.5-4580 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4590 (including) | 4.5-4590 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4591 (including) | 4.5-4591 (including) |
Manageengine_adselfservice_plus | Zohocorp | 4.5-4592 (including) | 4.5-4592 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5000 (including) | 5.0-5000 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5001 (including) | 5.0-5001 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5002 (including) | 5.0-5002 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5010 (including) | 5.0-5010 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5011 (including) | 5.0-5011 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5020 (including) | 5.0-5020 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5021 (including) | 5.0-5021 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5022 (including) | 5.0-5022 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5030 (including) | 5.0-5030 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5032 (including) | 5.0-5032 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5040 (including) | 5.0-5040 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0-5041 (including) | 5.0-5041 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.0.6 (including) | 5.0.6 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5100 (including) | 5.1-5100 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5101 (including) | 5.1-5101 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5102 (including) | 5.1-5102 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5103 (including) | 5.1-5103 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5104 (including) | 5.1-5104 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5105 (including) | 5.1-5105 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5106 (including) | 5.1-5106 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5107 (including) | 5.1-5107 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5108 (including) | 5.1-5108 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5109 (including) | 5.1-5109 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5110 (including) | 5.1-5110 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5111 (including) | 5.1-5111 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5112 (including) | 5.1-5112 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5113 (including) | 5.1-5113 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5114 (including) | 5.1-5114 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5115 (including) | 5.1-5115 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.1-5116 (including) | 5.1-5116 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5200 (including) | 5.2-5200 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5201 (including) | 5.2-5201 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5202 (including) | 5.2-5202 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5203 (including) | 5.2-5203 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5204 (including) | 5.2-5204 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5205 (including) | 5.2-5205 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5206 (including) | 5.2-5206 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.2-5207 (including) | 5.2-5207 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5300 (including) | 5.3-5300 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5301 (including) | 5.3-5301 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5302 (including) | 5.3-5302 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5303 (including) | 5.3-5303 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5304 (including) | 5.3-5304 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5305 (including) | 5.3-5305 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5306 (including) | 5.3-5306 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5307 (including) | 5.3-5307 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5308 (including) | 5.3-5308 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5309 (including) | 5.3-5309 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5310 (including) | 5.3-5310 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5311 (including) | 5.3-5311 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5312 (including) | 5.3-5312 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5313 (including) | 5.3-5313 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5314 (including) | 5.3-5314 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5315 (including) | 5.3-5315 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5316 (including) | 5.3-5316 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5317 (including) | 5.3-5317 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5318 (including) | 5.3-5318 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5319 (including) | 5.3-5319 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5320 (including) | 5.3-5320 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5321 (including) | 5.3-5321 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5322 (including) | 5.3-5322 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5323 (including) | 5.3-5323 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5324 (including) | 5.3-5324 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5325 (including) | 5.3-5325 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5326 (including) | 5.3-5326 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5327 (including) | 5.3-5327 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5328 (including) | 5.3-5328 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5329 (including) | 5.3-5329 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.3-5330 (including) | 5.3-5330 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.4-5400 (including) | 5.4-5400 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5 (including) | 5.5 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5500 (including) | 5.5-5500 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5501 (including) | 5.5-5501 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5502 (including) | 5.5-5502 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5503 (including) | 5.5-5503 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5504 (including) | 5.5-5504 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5505 (including) | 5.5-5505 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5506 (including) | 5.5-5506 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5507 (including) | 5.5-5507 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5508 (including) | 5.5-5508 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5509 (including) | 5.5-5509 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5510 (including) | 5.5-5510 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5511 (including) | 5.5-5511 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5512 (including) | 5.5-5512 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5513 (including) | 5.5-5513 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5514 (including) | 5.5-5514 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5515 (including) | 5.5-5515 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5516 (including) | 5.5-5516 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5517 (including) | 5.5-5517 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5518 (including) | 5.5-5518 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5519 (including) | 5.5-5519 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5520 (including) | 5.5-5520 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.5-5521 (including) | 5.5-5521 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5600 (including) | 5.6-5600 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5601 (including) | 5.6-5601 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5602 (including) | 5.6-5602 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5603 (including) | 5.6-5603 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5604 (including) | 5.6-5604 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5605 (including) | 5.6-5605 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5606 (including) | 5.6-5606 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.6-5607 (including) | 5.6-5607 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5607 (including) | 5.7-5607 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5700 (including) | 5.7-5700 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5701 (including) | 5.7-5701 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5702 (including) | 5.7-5702 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5703 (including) | 5.7-5703 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5704 (including) | 5.7-5704 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5705 (including) | 5.7-5705 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5706 (including) | 5.7-5706 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5707 (including) | 5.7-5707 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5708 (including) | 5.7-5708 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5709 (including) | 5.7-5709 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.7-5710 (including) | 5.7-5710 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8 (including) | 5.8 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5800 (including) | 5.8-5800 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5801 (including) | 5.8-5801 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5802 (including) | 5.8-5802 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5803 (including) | 5.8-5803 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5804 (including) | 5.8-5804 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5805 (including) | 5.8-5805 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5806 (including) | 5.8-5806 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5807 (including) | 5.8-5807 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5808 (including) | 5.8-5808 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5809 (including) | 5.8-5809 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5810 (including) | 5.8-5810 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5811 (including) | 5.8-5811 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5812 (including) | 5.8-5812 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5813 (including) | 5.8-5813 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5814 (including) | 5.8-5814 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5815 (including) | 5.8-5815 (including) |
Manageengine_adselfservice_plus | Zohocorp | 5.8-5816 (including) | 5.8-5816 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0 (including) | 6.0 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6000 (including) | 6.0-6000 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6001 (including) | 6.0-6001 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6002 (including) | 6.0-6002 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6003 (including) | 6.0-6003 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6004 (including) | 6.0-6004 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6005 (including) | 6.0-6005 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6006 (including) | 6.0-6006 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6007 (including) | 6.0-6007 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6008 (including) | 6.0-6008 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6009 (including) | 6.0-6009 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6012 (including) | 6.0-6012 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.0-6013 (including) | 6.0-6013 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.1 (including) | 6.1 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.1-6100 (including) | 6.1-6100 (including) |
Manageengine_adselfservice_plus | Zohocorp | 6.1-6101 (including) | 6.1-6101 (including) |
This could allow attackers to execute unexpected, dangerous commands directly on the operating system. This weakness can lead to a vulnerability in environments in which the attacker does not have direct access to the operating system, such as in web applications. Alternately, if the weakness occurs in a privileged program, it could allow the attacker to specify commands that normally would not be accessible, or to call alternate commands with privileges that the attacker does not have. The problem is exacerbated if the compromised process does not follow the principle of least privilege, because the attacker-controlled commands may run with special system privileges that increases the amount of damage. There are at least two subtypes of OS command injection:
From a weakness standpoint, these variants represent distinct programmer errors. In the first variant, the programmer clearly intends that input from untrusted parties will be part of the arguments in the command to be executed. In the second variant, the programmer does not intend for the command to be accessible to any untrusted party, but the programmer probably has not accounted for alternate ways in which malicious attackers can provide input.