Pricing  Get Quote
 
 

How to identify and mitigate the unauthenticated product integration vulnerability

Some versions of ADSelfService Plus have the unauthenticated change to integration system vulnerability. This article explains how you can identify if your ADSelfService Plus installation is affected, and fix it. It also offers the mitigation steps to protect your installation in case it is not affected.

What is the issue?

ADSelfService Plus had a vulnerable endpoint which allowed a user to integrate ADSelfService Plus with any other supported ManageEngine product, bypassing authentication. This could lead to data leak.

Which version of ADSelfService Plus is affected?

All ADSelfService Plus builds below 5817 are affected.

What is the severity level of the vulnerability?

This is a critical issue. As this vulnerability could be exploited without authentication, from any publicly exposed ADSelfService Plus installation, the risks posed could be critical.

How do I fix this issue?

What should I do to protect ADSelfService Plus if, for some reason, I can't update?

We recommend that you follow the steps mentioned in this forum post. If, for any reason, you cannot do that, perform the following mitigation steps.

  1. Stop ADSelfService Plus.
  2. Remove or comment the following content from the file web.xml in the path \webapps\adssp\WEB-INF\web.xml.
    <!-- servlet-mapping>
    <servlet-name>UpdateProductDetails</servlet-name>
    <url-pattern>/servlet/UpdateProductDetails</url-pattern>
    </servlet-mapping>

    <servlet-mapping>
    <servlet-name>HSKeyAuthenticator</servlet-name>
    <url-pattern>/servlet/HSKeyAuthenticator</url-pattern>
    </servlet-mapping>

    <servlet>
    <servlet-name>HSKeyAuthenticator</servlet-name>
    <servlet-class>com.manageengine.ads.fw.servlet.HSKeyAuthenticator</servlet-class>
    </servlet>

    <servlet>
    <servlet-name>UpdateProductDetails</servlet-name>
    <servlet-class>com.manageengine.ads.fw.servlet.UpdateProductDetails</servlet-class>
    </servlet>-->

    Note: Deleting or commenting these will disable the data synchronization and flow of data with the integrated products.

  3. Restart ADSelfService Plus.

If you need further information, have any questions, or face any difficulties upgrading or performing the recommended steps, please get in touch with us at support@adselfserviceplus.com, or 1-888-720-9500 (toll free).

Request for Support

Need further assistance? Fill this form, and we'll contact you rightaway.

  • Name
  •  
  • Business Email *
  •  
  • Phone *
  •  
  • Problem Description *
  •  
  • Country
  •  
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.
Highlights

Password self-service

Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks. Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console. 

One identity with Single sign-on

Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus! 

Password/Account Expiry Notification

Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.

Password Synchronizer

Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, including Office 365, G Suite, IBM iSeries and more. 

Password Policy Enforcer

Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.

Directory Self-UpdateCorporate Search

Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.

ADSelfService Plus trusted by

Embark on a journey towards identity security and Zero Trust