Summary
Security update fixes a “High” severity vulnerability in ManageEngine ADSelfService Plus. This vulnerability, if exploited, could allow an attacker to take control of user accounts on the target system.
Risk
Community Impact Estimation: Medium (64.23)
Type
- Authentication Bypass
- Security Restrictions Bypass
Affected Products and Versions
ManageEngine ADSelfService Plus, versions prior to build 6511
Mitigation Actions
In line with vendor statements, it is recommended to update vulnerable products as indicated in the security bulletins reported in the References section.
References
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.