PT-2026-51487 · Manageengine · Ad360+4
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ADSelfService Plus versions prior to 6529
RecoveryManager Plus versions prior to 6321
M365 Manager Plus versions prior to 4817
ADAudit Plus versions prior to 8703
Description
In ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus (when deployed as integrated components within ManageEngine AD360), SSO tickets generated for session authentication can be predicted by an unauthenticated user. This allows an attacker to obtain a targeted user's identity and role information, leading to full account takeover and compromise of confidentiality, integrity, and availability across the affected systems.
Recommendations
Update ADSelfService Plus to version 6529 or later.
Update RecoveryManager Plus to version 6321 or later.
Update M365 Manager Plus to version 4817 or later.
Update ADAudit Plus to version 8703 or later.
Fix
Use of Insufficiently Random Values
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ad360
Adaudit Plus
Adselfservice Plus
O365 Manager Plus
Recovermanager Plus