Schedule demo
 
 

CVE-2022-23050

An Authenticated administrator user can upload a script/DLL file inside working directory. Upon restart the uploaded files might be executed leading to Remote Code Execution (RCE).

Vulnerability Details
Impact CVSS V3 rating: 7.2
Fixed 15 February 2022
Affected Builds Version 15510 and below
Fixed in Version 15511 and above
Overview Insecure file upload by an authenticated admin user.
Recommended Fix Upgrade Applications Manager to version 15511 or above.

Description - Security Update - CVE-2022-23050 Database

ManageEngine AppManager15 allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.

We recommend you to upgrade Applications Manager to version 15511 or above to fix this issue.

Source and Acknowledgements

Find out more about CVE-2022-23050 from CVE Directory and NIST NVD.

Reported by:
Oscar

Need Help?

For clarification or corrections please contact our support team or email us at appmanager-support@manageengine.com

Loved by customers all over the world

"Standout Tool With Extensive Monitoring Capabilities"

It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.

Reviewer Role: Research and Development

"I like Applications Manager because it helps us to detect issues present in our servers and SQL databases."
Carlos Rivero

Tech Support Manager, Lexmark

Trusted by over 6000+ businesses globally