Schedule demo
 
 

CVE-2022-23050

An Authenticated administrator user can upload a script/DLL file inside working directory. Upon restart the uploaded files might be executed leading to Remote Code Execution (RCE).

Vulnerability Details
Impact CVSS V3 rating:
Fixed 15 February 2022
Affected Builds Version 15510 and below
Fixed in Version 15511 and above
Overview Insecure file upload by an authenticated admin user.
Recommended Fix Upgrade Applications Manager to version 15511 or above.

Description - Security Update - CVE-2022-23050 Database

ManageEngine AppManager15 allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.

We recommend you to upgrade Applications Manager to version 15511 or above to fix this issue.

Source and Acknowledgements

Find out more about CVE-2022-23050 from CVE Directory and NIST NVD.

Reported by:
Oscar

Need Help?

For clarification or corrections please contact our support team or email us at appmanager-support@manageengine.com

You'll be in great company