S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-28219 Scanner

Detects 'XML External Entity (XXE)' vulnerability in Zoho ManageEngine ADAudit Plus affects v. before 7060.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-28219
9.8
CVSS

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Zoho ManageEngine ADAudit Plus is a comprehensive IT audit and compliance tool that helps organizations monitor and manage their network security. It is designed to audit and track all changes made to the Active Directory, Azure AD, Windows servers, Exchange servers, and other critical systems. The tool offers various features, including real-time alerts, scheduled reports, and rich visual analysis, making it a valuable tool for IT administrators and security professionals.

However, the recent discovery of CVE-2022-28219 vulnerability in the Cewolf component of Zoho ManageEngine ADAudit Plus before version 7060 has raised serious concerns about the product's security. This vulnerability is an unauthenticated XML External Entity (XXE) attack that can be exploited by an attacker to remotely execute arbitrary code on the targeted system. This flaw arises due to insufficient validation of user-supplied XML data, which allows attackers to send malicious payloads to the server and can lead to severe consequences.

When exploited, the CVE-2022-28219 vulnerability can result in potential data breaches, network disruption, and catastrophic damage to the organization's reputation. An attacker with access to the system can exploit the vulnerability to access sensitive data, compromise user credentials, or hijack the system entirely, resulting in the loss of confidential data, financial loss, and legal issues.

In conclusion, security is a top priority for organizations, and Zoho ManageEngine ADAudit Plus is an essential tool that helps keep their IT systems under control. However, the recent discovery of the vulnerability has highlighted the importance of staying vigilant and taking the necessary precautions to mitigate risks. By leveraging s4e.io's pro features, the article's readers can quickly and easily learn about vulnerabilities in their digital assets and take proactive measures to keep their systems secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Zoho ManageEngine ADAudit Plus users can take the following precautions:

  • Upgrade to the latest version of the product (7060 or later) as it contains a fix for the vulnerability.
  • Deploy firewalls and intrusion detection systems to identify and prevent suspicious activity and malicious payloads in network traffic.
  • Restrict access to the product to authorized personnel only.
  • Monitor logs and audit trails for any suspicious activity.
  • Implement proper security protocols, policies, and procedures to ensure the safety and security of the IT environment.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.