First published: Tue Apr 05 2022(Updated: )
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADAudit Plus | <=6.0 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7000 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7002 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7003 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7004 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7005 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7006 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7007 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7008 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7050 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7051 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7052 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7053 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7054 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-24978.
The severity level of CVE-2022-24978 is high.
CVE-2022-24978 allows authenticated Privilege Escalation on Integrated products because a password field is present in a JSON response.
Zoho ManageEngine ADAudit Plus versions up to 6.0 and versions 7.0-7000 to 7.0-7054 are affected by CVE-2022-24978.
To fix CVE-2022-24978, it is recommended to upgrade to a patched version of Zoho ManageEngine ADAudit Plus.