Emergency assistance for ADManager Plus vulnerability (CVE-2021-42002)
This vulnerability has been fixed. Update to ADManager Plus build 7117 immediately.
An authentication bypass vulnerability (CVE-2021-42002), that affects the REST API URLs that could result in remote code execution (RCE), was identified in ADManager Plus, ManageEngine's Active Directory (AD) management and reporting solution. This vulnerability has been addressed. ManageEngine strongly urges users and administrators to upgrade to ADManager Plus build 7117.
ADManager Plus build 7117 fixes CVE-2021-42002. ManageEngine strongly urges users and administrators to update to ADManager Plus build 7117.
Our security advisory covers the details of the vulnerability, a tool to check if your installation is affected, indicators of compromise (IOCs), and an incident response plan for quick remediation.
Read the advisoryUse the exploit detection tool to run a quick scan and discover any compromises in your installation. The tool checks for the presence of any IOCs associated with the vulnerability CVE-2021-42002 and notifies you if your system is infected.
Download the tool and check for IOCsWatch how to detect and mitigate any compromises in your installation.
CVE-2021-42002 is an authentication bypass vulnerability concerning the REST API URLs in ADManager Plus. This issue allows attackers to gain unauthorized access to the product through REST API endpoints by sending a specially crafted request. This would allow the attacker to carry out subsequent attacks and perform RCE.
ADManager Plus builds up to 7114 are vulnerable.
ManageEngine has developed a tool to check if an ADManager Plus installation has been affected by this vulnerability. Follow the below steps to install and run the tool to check your instance.
(or)
In \ManageEngine\ADManager Plus\logs folder, search the access log entries for the below strings:
The image below shows the access log entry:
There is a possibility that your ADManager Plus server setup has been exploited if you find any of the above entries in the logs.
Implement the remediation steps provided below at the earliest possible time.
Follow the steps below to update ADManager Plus to build 7117 or above:
To find your current build number, log in to the ADManager Plus web client, and click the "License" link in the top pane. You'll find the build number in the License Details popup.
Currently, there are no workarounds to address this vulnerability. ManageEngine strongly recommends that you update ADManager Plus to the latest build as soon as possible.
The authentication bypass vulnerability has been fixed in ADManager Plus builds 7117 and above.
ManageEngine has also developed an exploit detection tool that makes it easier for users to check if their installation has been affected by this vulnerability. We've also released a security advisory to help you immediately address this vulnerability.
For immediate support regarding this issue, customers can get in touch with us at support@admanagerplus.com or +1-312-471-2233 (toll-free).
Various security enhancements have been made to ADManager Plus. We've also added a provision to check the Product Security Score and take measures to improve the security configurations of the product.
In the event of an exploit, or if you're worried and just want to make sure that your installation is vulnerability-free and secure, register below for a complimentary audit. Our cybersecurity team will provide personal assistance.
Thank you for registering for our vulnerability audit. Our cybersecurity team will soon contact you to provide personal assistance.
Thank you for downloading this e-book. Please check your Inbox (or spam) to access this e-book.