Vulnerability record · CVE-2022-42904 · published 18 November 2022
CVE-2022-42904: Zoho ManageEngine ADManager Plus command injection in proxy settings
Zohocorp · Manageengine Admanager Plus
ADManager Plus through build 7151 lets an authenticated administrator execute arbitrary commands through the proxy settings. Because the flaw is command injection reachable over the network, an admin account becomes a path to full command execution on the server.
Description
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution with high CIA impact, though it requires an authenticated admin account and no known exploitation is documented.
What it is
ADManager Plus through build 7151 lets an authenticated administrator execute arbitrary commands through the proxy settings. Because the flaw is command injection reachable over the network, an admin account becomes a path to full command execution on the server.
Impact
An attacker with admin access gains remote command execution on the ADManager Plus host, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the server and any credentials or directory data it manages.
Attack surface
Reachable over the network via the proxy settings interface; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N). Only an authenticated admin can reach the vulnerable functionality.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.83, 99.7th percentile), indicating elevated predicted exploitation activity, but the record provides no public exploit reference.
What to do
- Upgrade ADManager Plus past build 7151 using the vendor advisory/release notes.
- Restrict and audit admin accounts; enforce least privilege and remove unused admin access.
- Limit network exposure of the ADManager Plus web interface to trusted management networks.
- Monitor and review proxy setting changes and any command execution on the host.
- Apply MFA and strong authentication for administrative logins.
Detection
- Alert on changes to proxy configuration settings in ADManager Plus.
- Monitor server process creation for unexpected child processes spawned by the ADManager Plus service.
- Audit admin account activity and logins for anomalous or out-of-hours use.
- Review web server and application logs for requests to proxy settings endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2022-42904.html | Release NotesVendor Advisory |
| https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2022-42904.html | Release NotesVendor Advisory |
Track CVE-2022-42904 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42904), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.