Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_admanager_plus | Zohocorp | * | 7.1 (excluding) |
Manageengine_admanager_plus | Zohocorp | 7.1 (including) | 7.1 (including) |
Manageengine_admanager_plus | Zohocorp | 7.1-7100 (including) | 7.1-7100 (including) |
Manageengine_admanager_plus | Zohocorp | 7.1-7101 (including) | 7.1-7101 (including) |
Manageengine_admanager_plus | Zohocorp | 7.1-7102 (including) | 7.1-7102 (including) |
Manageengine_admanager_plus | Zohocorp | 7.1-7110 (including) | 7.1-7110 (including) |