QID 376525
Date Published: 2022-04-11
QID 376525: Zoho ManageEngine ADAudit Plus Remote Code Execution (RCE) Vulnerability
ManageEngine ADAudit Plus is a Windows auditing, security, and compliance solution.
Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Affected Versions:
Prior to build 7060
QID Detection Logic:
.
Authenticated : This QID checks for file modified date to check if latest build is installed
ManageEngine ADAudit Plus had vulnerable endpoints that allowed an unauthenticated attacker to exploit XML External Entities (XXE), Java deserialization and path traversal vulnerabilities. The chain could be leveraged to unauthenticated remote code execution.
Solution
Customers are advised to refer to ManageEngine ADAudit Plus for information pertaining to this vulnerability.
Vendor References
CVEs related to QID 376525
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ADAudit Plus |
|