CVE-2022-29457: High severity zoho manageengine adaudit plus vulnerability

Published Apr 18, 2022
·
Updated

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

Affected Software

64 affected components
Zohocorp ManageEngine ADAudit Plus<7.0.0
Zohocorp ManageEngine ADAudit Plus=7.0.0
Zohocorp ManageEngine ADAudit Plus=7.0.0-7000
Zohocorp ManageEngine ADAudit Plus=7.0.0-7002
Zohocorp ManageEngine ADAudit Plus=7.0.0-7003
Zohocorp ManageEngine ADAudit Plus=7.0.0-7004
Zohocorp ManageEngine ADAudit Plus=7.0.0-7005
Zohocorp ManageEngine ADAudit Plus=7.0.0-7006
Zohocorp ManageEngine ADAudit Plus=7.0.0-7007
Zohocorp ManageEngine ADAudit Plus=7.0.0-7008
Zohocorp ManageEngine ADAudit Plus=7.0.0-7050
Zohocorp ManageEngine ADAudit Plus=7.0.0-7051
Zohocorp ManageEngine ADAudit Plus=7.0.0-7052
Zohocorp ManageEngine ADAudit Plus=7.0.0-7053
Zohocorp ManageEngine ADAudit Plus=7.0.0-7054
Zohocorp ManageEngine ADAudit Plus=7.0.0-7055
Zohocorp ManageEngine ADManager Plus<7.1
Zohocorp ManageEngine ADManager Plus=7.1
Zohocorp ManageEngine ADManager Plus=7.1-7100
Zohocorp ManageEngine ADManager Plus=7.1-7101
Zohocorp ManageEngine ADManager Plus=7.1-7102
Zohocorp ManageEngine ADManager Plus=7.1-7110
Zohocorp ManageEngine ADManager Plus=7.1-7111
Zohocorp ManageEngine ADManager Plus=7.1-7112
Zohocorp ManageEngine ADManager Plus=7.1-7113
Zohocorp ManageEngine ADManager Plus=7.1-7114
Zohocorp ManageEngine ADManager Plus=7.1-7115
Zohocorp ManageEngine ADManager Plus=7.1-7116
Zohocorp ManageEngine ADManager Plus=7.1-7117
Zohocorp ManageEngine ADManager Plus=7.1-7118
Zohocorp ManageEngine ADManager Plus=7.1-7120
Zohocorp ManageEngine ADManager Plus=7.1-7121
Zohocorp ManageEngine ADManager Plus=7.1-7122
Zohocorp ManageEngine ADManager Plus=7.1-7123
Zohocorp ManageEngine ADManager Plus=7.1-7124
Zohocorp ManageEngine ADManager Plus=7.1-7125
Zohocorp ManageEngine ADManager Plus=7.1-7126
Zohocorp ManageEngine ADManager Plus=7.1-7130
ZohoCorp ManageEngine ADSelfService Plus<6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1-6100
ZohoCorp ManageEngine ADSelfService Plus=6.1-6101
ZohoCorp ManageEngine ADSelfService Plus=6.1-6102
ZohoCorp ManageEngine ADSelfService Plus=6.1-6103
ZohoCorp ManageEngine ADSelfService Plus=6.1-6104
ZohoCorp ManageEngine ADSelfService Plus=6.1-6105
ZohoCorp ManageEngine ADSelfService Plus=6.1-6106
ZohoCorp ManageEngine ADSelfService Plus=6.1-6107
ZohoCorp ManageEngine ADSelfService Plus=6.1-6108
ZohoCorp ManageEngine ADSelfService Plus=6.1-6109
ZohoCorp ManageEngine ADSelfService Plus=6.1-6110
ZohoCorp ManageEngine ADSelfService Plus=6.1-6111
ZohoCorp ManageEngine ADSelfService Plus=6.1-6112
ZohoCorp ManageEngine ADSelfService Plus=6.1-6113
ZohoCorp ManageEngine ADSelfService Plus=6.1-6114
ZohoCorp ManageEngine ADSelfService Plus=6.1-6115
ZohoCorp ManageEngine ADSelfService Plus=6.1-6116
ZohoCorp ManageEngine ADSelfService Plus=6.1-6117
ZohoCorp ManageEngine ADSelfService Plus=6.1-6118
ZohoCorp ManageEngine ADSelfService Plus=6.1-6119
ZohoCorp ManageEngine ADSelfService Plus=6.1-6120
Zohocorp ManageEngine Exchange Reporter Plus<5.7
Zohocorp ManageEngine Exchange Reporter Plus=5.7
Zohocorp ManageEngine Exchange Reporter Plus=5.7-5700

Event History

Apr 18, 2022
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-29457?

CVE-2022-29457 is considered a critical vulnerability due to the potential exposure of NTLM hashes.

2

How do I fix CVE-2022-29457?

To fix CVE-2022-29457, upgrade to the latest version of the affected ManageEngine products as specified in their release notes.

3

What applications are affected by CVE-2022-29457?

CVE-2022-29457 affects ManageEngine ADSelfService Plus, ADAudit Plus, Exchange Reporter Plus, and ADManager Plus versions before specific patches.

4

What type of vulnerability is CVE-2022-29457?

CVE-2022-29457 is an information disclosure vulnerability that allows for NTLM Hash disclosure.

5

Is there a workaround for CVE-2022-29457?

There are no documented workarounds for CVE-2022-29457; updating to patched versions is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203