• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Zoho urges admins to patch severe ManageEngine bug immediately

Sergiu Gatlan by Sergiu Gatlan
January 5, 2023
Reading Time: 3 mins read
0
Zoho urges admins to patch critical ManageEngine bug immediately

Zoho

RELATED POSTS

Clop ransomware claims responsibility for MOVEit extortion attacks

Microsoft’s Outlook.com is down again on mobile, web

New tool scans iPhones for ‘Triangulation’ malware infection

Business software provider Zoho has urged customers to patch a high-severity security flaw affecting multiple ManageEngine products.

The bug, tracked as CVE-2022-47523, is an SQL injection vulnerability found in the company’s Password Manager Pro secure vault, PAM360 privileged access management software, and Access Manager Plus privileged session management solution.

Successful exploitation provides authenticated attackers with access to the backend database and allows them to execute custom queries to access database table entries.

“We identified a SQL injection vulnerability (CVE-2022-47523) in our internal framework that would grant access to all [..] users to the backend database,” Zoho said.

The company added that “given the severity of this vulnerability, customers are strongly advised to upgrade to the latest build of PAM360, Password Manager Pro and Access Manager Plus immediately.”

Zoho says it fixed the issue last month by escaping special characters and adding proper validation.

Buy JNews
ADVERTISEMENT

To upgrade your installation, you should first download the latest upgrade pack for your product (PAM360, Password Manager Pro, Access Manager Plus).

The next step is to deploy the latest build according to the upgrade instructions available on each product’s Upgrade Pack page.

Product Name Affected Versions Fixed Version Fixed On
Password Manager Pro 12200 and below 12210 30-12-2022
PAM360 5800 and below 5801 28-12-2022
Access Manager Plus 4308 and below 4309 29-12-2022

In September, CISA warned of another critical ManageEngine vulnerability (CVE-2022-35405) exploited in attacks to gain remote code execution on unpatched servers running PAM360, Access Manager Plus, and Password Manager Pro.

U.S. Federal Civilian Executive Branch Agencies (FCEB) agencies were given three weeks to patch vulnerable systems and ensure their networks would be protected from exploitation attempts.

Zoho ManageEngine servers have been under constant targeting in recent years, with Desktop Central instances, for instance, getting hacked and access to breached organizations’ networks sold on hacking forums starting in July 2020.

Between August and October 2021, nation-state hackers have also targeted ManageEngine servers using tactics and tooling similar to those of the Chinese-linked APT27 hacking group.

Following these extensive attack campaigns, the FBI and CISA issued two joint advisories [1, 2] warning of state-sponsored attackers exploiting ManageEngine bugs to backdoor the networks of critical infrastructure organizations.


Update January 05, 15:30 EST: Article and title revised after Zoho downgraded the flaw’s severity rating from Critical to High.

“Unfortunately, our team had incorrectly marked the severity of the vulnerability as ‘Critical’ in one of our advisory posts and stated that the vulnerability could allow unauthenticated access to the database,” a Zoho spokesperson told BleepingComputer.

“The vulnerability could only be exploited by an authenticated user and the severity of the issue is ‘High’. We have updated our advisory posts to reflect this information.”

Share54Tweet34Pin12
Sergiu Gatlan

Sergiu Gatlan

Related Posts

Hackers exploit Control Web Panel flaw to open reverse shells
Cyber Security

Clop ransomware claims responsibility for MOVEit extortion attacks

June 5, 2023
Outlook for Mac now free, Microsoft 365 subscription not needed
Cyber Security

Microsoft’s Outlook.com is down again on mobile, web

June 5, 2023
New tool scans iPhones for ‘Triangulation’ malware infection
Cyber Security

New tool scans iPhones for ‘Triangulation’ malware infection

June 5, 2023
New AhRat Android malware hidden in app with 50,000 installs
Cyber Security

SpinOk Android malware found in more apps with 30 million installs

June 5, 2023
GIGABYTE releases new firmware to fix recently disclosed security flaws
Cyber Security

GIGABYTE releases new firmware to fix recently disclosed security flaws

June 5, 2023
Researchers secretly helped decrypt Zeppelin ransomware for 2 years
Cyber Security

KeePass v2.54 fixes bug that leaked cleartext master password

June 5, 2023

Recommended Stories

BlackLotus bootkit bypasses UEFI Secure Boot on patched Windows 11

Microsoft shares guidance to detect BlackLotus UEFI bootkit attacks

April 12, 2023
How to make money with ChatGPT

How to make money with ChatGPT

May 25, 2023
Aurora infostealer malware increasingly adopted by cybergangs

Aurora infostealer malware increasingly adopted by cybergangs

November 21, 2022

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • RedEyes hackers use new malware to steal data from Windows, phones

    136 shares
    Share 54 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • Litecoin’s upcoming halving and its effect on miners
  • Uniswap: What’s next as UNI’s plunge hits range low
  • Polygon zkEVM’s growth unhindered: What it means for MATIC

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?