HTTP: Zoho ManageEngine ADAudit Plus ProcessTrackingListener External Entity Injection

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine ADAudit Plus. A successful attack can lead to arbitrary code execution.

Extended Description

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

Affected Products

Zohocorp manageengine_adaudit_plus

Short Name
HTTP:CTS:ZOHO-ADAUDIT-PTL-XXE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ADAudit CVE-2022-28219 Entity External Injection ManageEngine Plus ProcessTrackingListener Zoho
Release Date
07/21/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3716
False Positive
Unknown
Vendors

Zohocorp

Found a potential security threat?