CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
Tags
attack-pattern: | Data Credentials - T1589.001 Scheduled Task - T1053.005 Server - T1583.004 Server - T1584.004 Tool - T1588.002 Vulnerabilities - T1588.006 Scheduled Task - T1053 |
Common Information
Type | Value |
---|---|
UUID | f5c334ae-bb38-45be-b0e0-920d41d9c2a8 |
Fingerprint | 1f3384cccd270484 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 29, 2022, 1:13 p.m. |
Added to db | Jan. 19, 2023, 12:13 a.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus |
Title | CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus |
Detected Hints/Tags/Attributes | 45/1/25 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 3 | cve-2022-28219 |
|
Details | CVE | 24 | cve-2020-10189 |
|
Details | Domain | 1 | smoke.net |
|
Details | Domain | 1 | xxe-ftp-server.py |
|
Details | Domain | 27 | responder.py |
|
Details | File | 40 | web.xml |
|
Details | File | 8 | a.png |
|
Details | File | 2 | payload.json |
|
Details | File | 312 | calc.exe |
|
Details | File | 4 | 6-snapshot-all.jar |
|
Details | File | 1 | xxe-upload-test.jar |
|
Details | File | 1 | payload_jar.json |
|
Details | File | 12 | myfile.txt |
|
Details | File | 1 | xxe-ftp-server.py |
|
Details | File | 1 | payload_list.json |
|
Details | File | 1 | jar_cache7858836562026605742.tmp |
|
Details | File | 25 | responder.py |
|
Details | File | 1 | payload_ntlm.json |
|
Details | IPv4 | 1 | 10.0.220.200 |
|
Details | IPv4 | 1 | 10.0.220.100 |
|
Details | Url | 1 | http://10.0.220.100:8081/api/agent/tabs/agentdata |
|
Details | Url | 1 | http://10.0.220.200:9090/xxe-upload-test.jar!/myfile.txt |
|
Details | Url | 1 | http://10.0.220.200:3000/data.dtd |
|
Details | Url | 1 | http://10.0.220.100:8081/cewolf/a.png?img=/../../../../../../../../../users/a-jsmith/appdata/local/temp/jar_cache7858836562026605742.tmp |
|
Details | Url | 1 | http://10.0.220.200 |