Some versions of ADSelfService Plus have the unauthenticated change to integration system vulnerability. This article explains how you can identify if your ADSelfService Plus installation is affected, and fix it. It also offers the mitigation steps to protect your installation in case it is not affected.
ADSelfService Plus had a vulnerable endpoint which allowed a user to integrate ADSelfService Plus with any other supported ManageEngine product, bypassing authentication. This could lead to data leak.
All ADSelfService Plus builds below 5817 are affected.
This is a critical issue. As this vulnerability could be exploited without authentication, from any publicly exposed ADSelfService Plus installation, the risks posed could be critical.
We recommend that you follow the steps mentioned in this forum post. If, for any reason, you cannot do that, perform the following mitigation steps.
Note: Deleting or commenting these will disable the data synchronization and flow of data with the integrated products.
If you need further information, have any questions, or face any difficulties upgrading or performing the recommended steps, please get in touch with us at support@adselfserviceplus.com, or 1-888-720-9500 (toll free).
Need further assistance? Fill this form, and we'll contact you rightaway.
Allow Active Directory users to self-service their password resets and account unlock tasks, freeing them from lengthy help desk calls.
Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications using their Active Directory credentials.
Intimate Active Directory users of their impending password and account expiry via email and SMS notifications.
Synchronize Windows Active Directory user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.
Strong passwords resist various hacking threats. Enforce Active Directory users to adhere to compliant passwords by displaying password complexity requirements.
Enable Active Directory users to update their latest information themselves. Quick search features help admins scout for information using search keys like contact numbers.