First published: Tue Apr 05 2022(Updated: )
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADAudit Plus | <=6.0 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7000 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7002 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7003 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7004 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7005 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7006 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7007 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7008 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7050 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7051 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7052 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7053 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7054 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28219 is a vulnerability in Cewolf in Zoho ManageEngine ADAudit Plus that allows an unauthenticated XXE attack leading to remote code execution.
CVE-2022-28219 has a severity rating of 9.8, which is considered critical.
The vulnerability in CVE-2022-28219 can be exploited through an unauthenticated XXE attack.
The affected software is Zoho ManageEngine ADAudit Plus versions up to 6.0 and versions 7.0-7000 to 7.0-7054.
To fix the vulnerability in CVE-2022-28219, it is recommended to update Zoho ManageEngine ADAudit Plus to version 7.0-7060 or later.