Aller au contenu

Fiche vulnérabilité

CVE-2022-36412 : faille critique zohocorp manageengine supportcenter plus (CVSS 9.8)

Description

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 juil. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • zohocorp manageengine supportcenter plus

Références

Rechercher une autre vulnérabilité dans la base CVE