CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
Common Information
Type Value
UUID f5c334ae-bb38-45be-b0e0-920d41d9c2a8
Fingerprint 1f3384cccd270484
Analysis status DONE
Considered CTI value 0
Text language
Published June 29, 2022, 1:13 p.m.
Added to db Jan. 19, 2023, 12:13 a.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
Title CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
Detected Hints/Tags/Attributes 45/1/25
Attributes
Details Type #Events CTI Value
Details CVE 3
cve-2022-28219
Details CVE 24
cve-2020-10189
Details Domain 1
smoke.net
Details Domain 1
xxe-ftp-server.py
Details Domain 27
responder.py
Details File 40
web.xml
Details File 8
a.png
Details File 2
payload.json
Details File 312
calc.exe
Details File 4
6-snapshot-all.jar
Details File 1
xxe-upload-test.jar
Details File 1
payload_jar.json
Details File 12
myfile.txt
Details File 1
xxe-ftp-server.py
Details File 1
payload_list.json
Details File 1
jar_cache7858836562026605742.tmp
Details File 25
responder.py
Details File 1
payload_ntlm.json
Details IPv4 1
10.0.220.200
Details IPv4 1
10.0.220.100
Details Url 1
http://10.0.220.100:8081/api/agent/tabs/agentdata
Details Url 1
http://10.0.220.200:9090/xxe-upload-test.jar!/myfile.txt
Details Url 1
http://10.0.220.200:3000/data.dtd
Details Url 1
http://10.0.220.100:8081/cewolf/a.png?img=/../../../../../../../../../users/a-jsmith/appdata/local/temp/jar_cache7858836562026605742.tmp
Details Url 1
http://10.0.220.200