PT-2026-2435 · Manageengine · Adselfservice Plus

CVE-2025-11250

·

Publicado

2026-01-13

·

Atualizado

2026-02-28

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ADSelfService Plus versions prior to 6519
Description ManageEngine ADSelfService Plus versions before 6519 are susceptible to an authentication bypass due to improper filter configurations. This allows unauthorized access. The issue is expected to be rapidly exploited.
Recommendations Update ManageEngine ADSelfService Plus to version 6519 or later.

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11250

Produtos afetados

Adselfservice Plus