CVE-2024-27310

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.4:6400:*:*:*:*:*:*

History

27 Nov 2024, 16:25

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.4:6400:*:*:*:*:*:*
References () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html - () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html - Vendor Advisory
First Time Zohocorp manageengine Adselfservice Plus
Zohocorp

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html - () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html -

07 Oct 2024, 20:15

Type Values Removed Values Added
Summary (en) Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP query. (en) Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
CWE CWE-400 CWE-90

07 Jun 2024, 09:15

Type Values Removed Values Added
CWE CWE-400

28 May 2024, 12:39

Type Values Removed Values Added
Summary
  • (es) Las versiones de Zoho ManageEngine ADSelfService Plus inferiores a 6401 son vulnerables al ataque de DOS debido a la consulta LDAP maliciosa.

27 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-27 18:15

Updated : 2024-11-27 16:25


NVD link : CVE-2024-27310

Mitre link : CVE-2024-27310

CVE.ORG link : CVE-2024-27310


JSON object : View

Products Affected

zohocorp

  • manageengine_adselfservice_plus
CWE
CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

NVD-CWE-Other