← Back

CVE-2024-0252

nvd nist
Published: Jan 11, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

Affected (3)

1 product
Manageengine Adselfservice Plus
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 6.4
Version 6.4 6400
Version 6.4 6401

References (2)

Source: 0fc0942c-577d-436f-ae8e-945763c79b02
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.