Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://www.manageengine.com | vendor advisory |
https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | vendor advisory |
https://www.manageengine.com/products/self-service-password/release-notes.html#6110 | not applicable vendor advisory |