CVE-2019-7161: Zohocorp ManageEngine Adselfservice Plus

High severity, CVSS 7.5. EPSS: 5.6% chance of exploitation in the next 30 days.

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: version 5.0 only; version 5.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.5 only; …

Published 2019-03-21. Last modified 2026-06-17.