ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
History

Wed, 18 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ManageEngine

Published: 2024-01-11T07:57:12.987Z

Updated: 2025-06-17T21:09:15.509Z

Reserved: 2024-01-05T17:59:42.780Z

Link: CVE-2024-0252

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:16.095Z

cve-icon NVD

Status : Modified

Published: 2024-01-11T08:15:35.933

Modified: 2024-11-21T08:46:09.167

Link: CVE-2024-0252

cve-icon Redhat

No data.