CVE-2022-24978
05.04.2022, 19:15
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_adaudit_plus | 𝑥 ≤ 6.0 |
| zohocorp | manageengine_adaudit_plus | 7.0:7000 |
| zohocorp | manageengine_adaudit_plus | 7.0:7002 |
| zohocorp | manageengine_adaudit_plus | 7.0:7003 |
| zohocorp | manageengine_adaudit_plus | 7.0:7004 |
| zohocorp | manageengine_adaudit_plus | 7.0:7005 |
| zohocorp | manageengine_adaudit_plus | 7.0:7006 |
| zohocorp | manageengine_adaudit_plus | 7.0:7007 |
| zohocorp | manageengine_adaudit_plus | 7.0:7008 |
| zohocorp | manageengine_adaudit_plus | 7.0:7050 |
| zohocorp | manageengine_adaudit_plus | 7.0:7051 |
| zohocorp | manageengine_adaudit_plus | 7.0:7052 |
| zohocorp | manageengine_adaudit_plus | 7.0:7053 |
| zohocorp | manageengine_adaudit_plus | 7.0:7054 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References