CVE-2022-23050: High severity manageengine applications manager vulnerability
Published May 24, 2022
·Updated
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
Affected Software
4 affected components
ZohoCorp ManageEngine Applications Manager>=15.0<15.5
ZohoCorp ManageEngine Applications Manager=15.5
ZohoCorp ManageEngine Applications Manager=15.5-build15500
ZohoCorp ManageEngine Applications Manager=15.5-build15510
Event History
May 24, 2022
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-23050.
2
What is the name of the affected software?
The affected software is Zohocorp Manageengine Applications Manager.
3
What is the severity rating of CVE-2022-23050?
CVE-2022-23050 has a severity rating of 7.2 (high).
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading a DLL file to perform a DLL hijack attack.
5
Are there any security updates available for CVE-2022-23050?
Yes, security updates for CVE-2022-23050 are available. Please refer to the ManageEngine website for more information.