An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.excellium-services.com/cert-xlm-advisory/cve-2019-7161/ | third party advisory |
https://www.manageengine.com/products/self-service-password/release-notes.html | release notes patch vendor advisory |