Headline
CVE-2022-23050: Security Updates - CVE Details - CVE-2022-23050
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the ‘working’ folder through the ‘Upload Files / Binaries’ functionality.
An Authenticated administrator user can upload a script/DLL file inside working directory. Upon restart the uploaded files might be executed leading to Remote Code Execution (RCE).
Vulnerability Details
Impact
CVSS V3 rating:
Fixed
15 February 2022
Affected Builds
Version 15510 and below
Fixed in
Version 15511 and above
Overview
Insecure file upload by an authenticated admin user.
Recommended Fix
Upgrade Applications Manager to version 15511 or above.
Description - Security Update - CVE-2022-23050 Database
ManageEngine AppManager15 allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the ‘working’ folder through the ‘Upload Files / Binaries’ functionality.
We recommend you to upgrade Applications Manager to version 15511 or above to fix this issue.
Source and Acknowledgements
Need Help?
For clarification or corrections please contact our support team or email us at [email protected]
Related news
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.