CVE-2022-36412

Severity
9.8CRITICAL
EPSS
1.9%
top 16.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateJul 27

Description

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wpcm-pg4g-v7c4: In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass2022-07-27
CVEList
CVE-2022-36412: In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass2022-07-26
CVE-2022-36412 (CRITICAL CVSS 9.8) | In Zoho ManageEngine SupportCenter | cvebase.io