Improper access control in ManageEngine Access Manager Plus - CVE-2022-29081

 

Improper access control in ManageEngine Access Manager Plus - CVE-2022-29081

Published: April 27, 2022


Vulnerability identifier: #VU62664
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29081
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in 7 REST API endpoints. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application, including service restart, dashboard access, license management, certificate manipulation, etc.


Affected software

ManageEngine Access Manager Plus

How to mitigate CVE-2022-29081

Install updates from vendor's website.

ManageEngine Access Manager Plus - update to 4.3 4302

External References

Related Security Bulletins