Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_admanager_plus | - | 8.0 |
| zohocorp / manageengine_admanager_plus | 8.0-8000 | 8.0-8000.x |
| zohocorp / manageengine_admanager_plus | 8.0-8001 | 8.0-8001.x |
| zohocorp / manageengine_admanager_plus | 8.0-8002 | 8.0-8002.x |
| zohocorp / manageengine_admanager_plus | 8.0-8010 | 8.0-8010.x |
| zohocorp / manageengine_admanager_plus | 8.0-8011 | 8.0-8011.x |
| zohocorp / manageengine_admanager_plus | 8.0-8012 | 8.0-8012.x |
| zohocorp / manageengine_admanager_plus | 8.0-8020 | 8.0-8020.x |
| zohocorp / manageengine_admanager_plus | 8.0-8021 | 8.0-8021.x |
| zohocorp / manageengine_admanager_plus | 8.0-8022 | 8.0-8022.x |