8.8
CWE
522
Advisory Published
Updated

CVE-2022-29457

First published: Mon Apr 18 2022(Updated: )

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zoho ManageEngine ADAudit Plus<7.0.0
Zoho ManageEngine ADAudit Plus=7.0.0
Zoho ManageEngine ADAudit Plus=7.0.0-7000
Zoho ManageEngine ADAudit Plus=7.0.0-7002
Zoho ManageEngine ADAudit Plus=7.0.0-7003
Zoho ManageEngine ADAudit Plus=7.0.0-7004
Zoho ManageEngine ADAudit Plus=7.0.0-7005
Zoho ManageEngine ADAudit Plus=7.0.0-7006
Zoho ManageEngine ADAudit Plus=7.0.0-7007
Zoho ManageEngine ADAudit Plus=7.0.0-7008
Zoho ManageEngine ADAudit Plus=7.0.0-7050
Zoho ManageEngine ADAudit Plus=7.0.0-7051
Zoho ManageEngine ADAudit Plus=7.0.0-7052
Zoho ManageEngine ADAudit Plus=7.0.0-7053
Zoho ManageEngine ADAudit Plus=7.0.0-7054
Zoho ManageEngine ADAudit Plus=7.0.0-7055
Zoho Corporation AdManager Plus<7.1
Zoho Corporation AdManager Plus=7.1
Zoho Corporation AdManager Plus=7.1-7100
Zoho Corporation AdManager Plus=7.1-7101
Zoho Corporation AdManager Plus=7.1-7102
Zoho Corporation AdManager Plus=7.1-7110
Zoho Corporation AdManager Plus=7.1-7111
Zoho Corporation AdManager Plus=7.1-7112
Zoho Corporation AdManager Plus=7.1-7113
Zoho Corporation AdManager Plus=7.1-7114
Zoho Corporation AdManager Plus=7.1-7115
Zoho Corporation AdManager Plus=7.1-7116
Zoho Corporation AdManager Plus=7.1-7117
Zoho Corporation AdManager Plus=7.1-7118
Zoho Corporation AdManager Plus=7.1-7120
Zoho Corporation AdManager Plus=7.1-7121
Zoho Corporation AdManager Plus=7.1-7122
Zoho Corporation AdManager Plus=7.1-7123
Zoho Corporation AdManager Plus=7.1-7124
Zoho Corporation AdManager Plus=7.1-7125
Zoho Corporation AdManager Plus=7.1-7126
Zoho Corporation AdManager Plus=7.1-7130
ADSelfService Plus<6.1
ADSelfService Plus=6.1
ADSelfService Plus=6.1-6100
ADSelfService Plus=6.1-6101
ADSelfService Plus=6.1-6102
ADSelfService Plus=6.1-6103
ADSelfService Plus=6.1-6104
ADSelfService Plus=6.1-6105
ADSelfService Plus=6.1-6106
ADSelfService Plus=6.1-6107
ADSelfService Plus=6.1-6108
ADSelfService Plus=6.1-6109
ADSelfService Plus=6.1-6110
ADSelfService Plus=6.1-6111
ADSelfService Plus=6.1-6112
ADSelfService Plus=6.1-6113
ADSelfService Plus=6.1-6114
ADSelfService Plus=6.1-6115
ADSelfService Plus=6.1-6116
ADSelfService Plus=6.1-6117
ADSelfService Plus=6.1-6118
ADSelfService Plus=6.1-6119
ADSelfService Plus=6.1-6120
ManageEngine Exchange Reporter Plus<5.7
ManageEngine Exchange Reporter Plus=5.7
ManageEngine Exchange Reporter Plus=5.7-5700

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-29457?

    CVE-2022-29457 is considered a critical vulnerability due to the potential exposure of NTLM hashes.

  • How do I fix CVE-2022-29457?

    To fix CVE-2022-29457, upgrade to the latest version of the affected ManageEngine products as specified in their release notes.

  • What applications are affected by CVE-2022-29457?

    CVE-2022-29457 affects ManageEngine ADSelfService Plus, ADAudit Plus, Exchange Reporter Plus, and ADManager Plus versions before specific patches.

  • What type of vulnerability is CVE-2022-29457?

    CVE-2022-29457 is an information disclosure vulnerability that allows for NTLM Hash disclosure.

  • Is there a workaround for CVE-2022-29457?

    There are no documented workarounds for CVE-2022-29457; updating to patched versions is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203