There is a vulnerability in Zoho’s compliance tool, ManageEngine ADAudit Plus. The tool monitors changes to Microsoft Active Directory and leaves endpoints vulnerable to unauthenticated users. The vulnerability could allow an attack to take over an entire enterprise network. The tool offers a path into a company’s workstations, file serves, and overall servers. The tool allows IT admin to access a range of users, groups, permissions, and login information as well as security policies. Users can also collect security events from agents running on other machines in the domain. The platform’s ability to provide access into an internal IT ecosystem increases the potential for a high-level data exposure should a breach occur. A CVE-2022-28219 vulnerability would allow malicious users to take over a network and deploy ransomware, exfiltrate business data, or disrupt operations. They could also exploit XML External Entities, Java deserialization and cause additional problems.
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |