CVE-2021-31874
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

Zoho ManageEngine ADSelfService Plus before version 6104 contained a vulnerability (CVE-2021-31874) that allowed attackers to obtain sensitive information about the password-sync database application. The vulnerability was discovered in March 2021 and was fixed in build 6104 released in May 2021 (ManageEngine Release, STM Cyber).

Technical details

The vulnerability exists in the account linking process with external databases. When linking an account, the HOST_NAME parameter, which contains the IP address of the database, could be manipulated. An attacker could specify any IP address, including that of a malicious server with a fake database. This would cause the ADSelfService Plus server to attempt authentication using administrator-stored credentials, thereby exposing them to the attacker. The vulnerability has a CVSS v3.1 score of 9.1 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L (STM Cyber).

Impact

The vulnerability allows attackers to retrieve credentials of configured database applications stored by administrators. This could lead to unauthorized access to sensitive database systems and potential compromise of connected infrastructure. The attack requires only low privileges and no user interaction, making it particularly dangerous (STM Cyber).

Exploitability

The vulnerability is confirmed to be exploitable in ADSelfService Plus versions prior to 6104. A proof-of-concept exploit has been publicly released demonstrating the vulnerability using PostgreSQL as an example. The exploit requires only valid user session cookies and can be executed remotely (STM Cyber).

Mitigation and workarounds

The vulnerability was fixed in ADSelfService Plus build 6104. Organizations should upgrade to this version or later to protect against this vulnerability. The fix prevents the processing of user-provided HOST_NAME parameters and instead uses the administrator-configured value (ManageEngine Release).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management