9.8

CVE-2022-28219

Exploit
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7000
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7002
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7003
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7004
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7005
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7006
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7007
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7008
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7050
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7051
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7052
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7053
Zohocorp ≫ Manageengine Adaudit Plus Version 7.0 Update 7054
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.19% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://manageengine.com
Vendor Advisory
http://cewolf.sourceforge.net/new/index.html
Third Party Advisory
Product
http://packetstormsecurity.com/files/167997/ManageEngine-ADAudit-Plus-Path-Traversal-XML-Injection.html
Third Party Advisory
Exploit
VDB Entry
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
Third Party Advisory
Exploit
https://www.manageengine.com/products/active-directory-audit/cve-2022-28219.html
Patch
Vendor Advisory