CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2022-35405

CVSS 9.8v3.1pub. 2022-07-19upd. 2025-10-31

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zohocorp Manageengine Access Manager Plus

    APP
    Zohocorp
    4.3< 4.3
  • Zohocorp Manageengine Pam360

    APP
    Zohocorp
    5.5< 5.5
  • Zohocorp Manageengine Password Manager Pro

    APP
    Zohocorp
    12.1< 12.1

CISA KEV — detailsi

Vendori
Zoho
Producti
ManageEngine
Added to KEVi
September 22, 2022
Remediation deadline (US Federal)i
October 13, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 13 października 2022
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product

RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec

CVE-2022-47523CRITICAL9.8PL ✓same product

SQL Injection w Zoho ManageEngine Access Manager Plus, Password Manager Pro i PAM360

CVE-2022-43672CRITICAL9.8PL ✓same product

SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus

CVE-2022-43671CRITICAL9.8PL ✓same product

SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus

CVE-2022-40300CRITICAL9.8PL ✓same product

SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus