|
|
|
|
| |
Credit:
The information has been provided by Ernesto lvarez.
The original article can be found at: http://www.coresecurity.com/content/zoho-manageengine-vulnerabilities
|
| |
Vulnerable Systems:
* ZOHO ManageEngine ADSelfService Plus 4.4.
Immune Systems:
* ZOHO ManageEngine ADSelfService Plus 4.5 Build 4500 and above.
The security question mechanism used for password recovery can be weakened by tampering the HTTP POST request containing the answers, allowing an attacker to pass the security check by guessing just one of the security answers. Additionally, the CAPTCHA mechanism can be bypassed in the same manner, enabling the automation of the guessing attempts.
The security question mechanism can also be bypassed by changing the flow of the application, skipping the security question mechanism and sending a HTTP request requiring the password change immediately after declaring which user is to run the recovery procedure.
Additionally, two cross site scripting vulnerabilities were found related to search functions.
ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management program. This software helps domain users to perform self service password reset, self service account unlock and employee self update of personal details (e.g. telephone numbers, etc) in Microsoft Windows Active Directory. Administrators find it easy to automate password resets, account unlocks while managing optimizing the expenses associated with helpdesk calls.
The security question mechanism used for password recovery can be weakened by tampering the HTTP POST request containing the answers, allowing an attacker to pass the security check by guessing just one of the security answers. Additionally, the CAPTCHA mechanism can be bypassed in the same manner, enabling the automation of the guessing attempts.
The security question mechanism can also be bypassed by changing the flow of the application, skipping the security question mechanism and sending a HTTP request requiring the password change immediately after declaring which user is to run the recovery procedure.
Additionally, two cross site scripting vulnerabilities were found related to search functions.
CVE Information:
CVE-2010-3272
CVE-2010-3273
CVE-2010-3274
Disclosure Timeline:
Date published: 2011-02-10
Date of last update: 2011-02-10
|
|
|
|
|