Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Security Updates

[CVE-2022-24978] Privilege Escalation Vulnerability fixed in build 7055

Severity: High

CVEID: CVE-2022-24978

Affected Software Version(s): Build 7054 and below

Fixed Version: Build 7055

Fixed on: 8th March, 2022

Details: CVE-2022-24978 refers to a privilege escalation vulnerability that allows a low privileged user to access the plain text password of the integrated ADManager Plus login account in ManageEngine ADAudit Plus. This issue has been fixed by removing the password field from the JSON response.

Impact: As the password is disclosed in plain text, a low privileged attacker can gain elevated privileges depending on the privileges of the integrated ADManager Plus login account.

Steps to upgrade: Update your ADAudit Plus instance to build 7055 using the service pack.

Acknowledgments: This issue was reported by Sahil Dhar.

Please contact support@adauditplus.com for more details.

ADAudit Plus Trusted By