#VU62664 Improper access control in ManageEngine Access Manager Plus - CVE-2022-29081

 

#VU62664 Improper access control in ManageEngine Access Manager Plus - CVE-2022-29081

Published: April 27, 2022


Vulnerability identifier: #VU62664
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2022-29081
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
ManageEngine Access Manager Plus
Software vendor:
ManageEngine

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in 7 REST API endpoints. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application, including service restart, dashboard access, license management, certificate manipulation, etc.


Remediation

Install updates from vendor's website.

External links