Vulnerability Description
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Adselfservice Plus | < 6.4 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-02Vendor Advisory
- https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-02Vendor Advisory
FAQ
What is CVE-2024-0252?
CVE-2024-0252 is a vulnerability with a CVSS score of 8.8 (HIGH). ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to ...
How severe is CVE-2024-0252?
CVE-2024-0252 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0252?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Adselfservice Plus.