CVE Vulnerabilities

CVE-2021-40539

Use of Incorrectly-Resolved Name or Reference

Published: Sep 07, 2021 | Modified: Nov 05, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Weakness

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_adselfservice_plusZohocorp*6.1 (excluding)
Manageengine_adselfservice_plusZohocorp6.1 (including)6.1 (including)
Manageengine_adselfservice_plusZohocorp6.1-6100 (including)6.1-6100 (including)
Manageengine_adselfservice_plusZohocorp6.1-6101 (including)6.1-6101 (including)
Manageengine_adselfservice_plusZohocorp6.1-6102 (including)6.1-6102 (including)
Manageengine_adselfservice_plusZohocorp6.1-6103 (including)6.1-6103 (including)
Manageengine_adselfservice_plusZohocorp6.1-6104 (including)6.1-6104 (including)
Manageengine_adselfservice_plusZohocorp6.1-6105 (including)6.1-6105 (including)
Manageengine_adselfservice_plusZohocorp6.1-6106 (including)6.1-6106 (including)
Manageengine_adselfservice_plusZohocorp6.1-6113 (including)6.1-6113 (including)

References