Fiche vulnérabilité
CVE-2022-36412 : faille critique zohocorp manageengine supportcenter plus (CVSS 9.8)
Description
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 juil. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zohocorp manageengine supportcenter plus