← Vulnerability feed

Vulnerability record · CVE-2022-42904 · published 18 November 2022

CVE-2022-42904: Zoho ManageEngine ADManager Plus command injection in proxy settings

Zohocorp · Manageengine Admanager Plus

ADManager Plus through build 7151 lets an authenticated administrator execute arbitrary commands through the proxy settings. Because the flaw is command injection reachable over the network, an admin account becomes a path to full command execution on the server.

7.2 CVSS 3.1 High EPSS 83% · top 0.3% CWE-77 · Command injection
7.2CVSS 3.1 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote command execution with high CIA impact, though it requires an authenticated admin account and no known exploitation is documented.

What it is

ADManager Plus through build 7151 lets an authenticated administrator execute arbitrary commands through the proxy settings. Because the flaw is command injection reachable over the network, an admin account becomes a path to full command execution on the server.

Impact

An attacker with admin access gains remote command execution on the ADManager Plus host, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the server and any credentials or directory data it manages.

Attack surface

Reachable over the network via the proxy settings interface; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N). Only an authenticated admin can reach the vulnerable functionality.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.83, 99.7th percentile), indicating elevated predicted exploitation activity, but the record provides no public exploit reference.

What to do

  • Upgrade ADManager Plus past build 7151 using the vendor advisory/release notes.
  • Restrict and audit admin accounts; enforce least privilege and remove unused admin access.
  • Limit network exposure of the ADManager Plus web interface to trusted management networks.
  • Monitor and review proxy setting changes and any command execution on the host.
  • Apply MFA and strong authentication for administrative logins.

Detection

  • Alert on changes to proxy configuration settings in ADManager Plus.
  • Monitor server process creation for unexpected child processes spawned by the ADManager Plus service.
  • Audit admin account activity and logins for anomalous or out-of-hours use.
  • Review web server and application logs for requests to proxy settings endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-42904 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-42002Zohocorp manageengine admanager plus vulnerabilityZoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.EPSS 7.5%9.8CVE-2021-38298Zohocorp manageengine admanager plus xml external entity (xxe) vulnerabilityZoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.EPSS 2.6%9.8CVE-2021-37762Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.EPSS 8.1%9.8CVE-2021-37918Zoho ManageEngine ADManager Plus unrestricted file upload RCEZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS…EPSS 74%analysed9.8CVE-2021-37919Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37920Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37921Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2022-42904), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.