The Exploit

Notes from the Front Lines of Penetration Testing

CVE-2022-25245: ManageEngine Asset Explorer Information Leakage

CVE-2022-25245: ManageEngine Asset Explorer Information Leakage

I’m Matt Dunn, a lead penetration tester at Raxis. Recently, I discovered an information leakage in ManageEngine Asset Explorer. This is a relatively minor information leakage, as it only leaks the currency that a current vendor uses. Though minor, it could lead to other inferred information such as vendor location based on their currency.

Proof of Concept

The information leakage occurs in the AJaxDomainServlet when given the action of getVendorCurrency. This servlet action does not require authentication, allowing a user to obtain a vendor’s currency with a GET request to a URL similar to the following:

http://192.168.148.128:8011/domainServlet/AJaxDomainServlet?action=getVendorCurrency&vendorId=3

In this example URL, we request the currency for the vendor with the specified vendorId. If the vendor doesn’t have an assigned currency, the dollar symbol is returned. If it does, the vendor’s specific currency identifier is returned, as shown here:

Vendor Currency Revealed in Unauthenticated Request
Affected Versions

Raxis discovered this vulnerability on Manage Engine Asset Explorer Plus 6.9 Build 6970.

Remediation

Upgrade ManageEngine Asset Explorer to Version 6.9 Build 6971 or later, which can be found here:

Disclosure Timeline
  • February 14, 2022 – Vulnerability reported to Zoho
  • February 15, 2022 – Zoho begins investigation into report
  • February 16, 2022 CVE-2022-25245 is assigned to this vulnerability
  • March 9, 2022 – Zoho releases fixed version 6.9 Build 6971
CVE Links

 


Raxis Administrator

Posted on

Categories:

Also by Raxis Administrator

Human Vs AI Pentesting

While AI tools offer speed in detecting known vulnerabilities, they fall short with 20-35% false positives and only 50-65% success on complex threats like business logic flaws, as per mainstream reports from Verizon and OWASP. Human penetration testers at Raxis deliver 85-90% detection rates, precise prioritization, and ethical adaptability, ensuring your organization stays ahead of real-world attacks.

Partner With Raxis

Partnering with Raxis empowers your business with elite penetration testing services, competitive reseller pricing, and recurring revenue opportunities, all backed by a proven track record of excellence and a commitment to staying ahead of evolving cybersecurity threats.

Penetration Testing

Tailored, expert-led penetration testing services that uncovers hidden vulnerabilities using real-world hacker techniques, providing actionable insights to strengthen your defenses and protect against sophisticated cyber threats.

Ready to See Raxis One In Action?

See how we transform traditional pen testing into interactive security intelligence that keeps you informed every step of the way. From real-time attack progression to detailed remediation guidance, Raxis One gives you unprecedented visibility into your security posture as it’s being tested.