Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Access Manager Plus
APPZohocorp4.3< 4.3Zohocorp Manageengine Pam360
APPZohocorp5.5< 5.5Zohocorp Manageengine Password Manager Pro
APPZohocorp12.1< 12.1
CISA KEV — detailsi
- Vendori
- Zoho ↗
- Producti
- ManageEngine
- Added to KEVi
- September 22, 2022
- Remediation deadline (US Federal)i
- October 13, 2022(overdue)
Apply updates per vendor instructions.
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
Related vulnerabilities
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
SQL Injection w Zoho ManageEngine Access Manager Plus, Password Manager Pro i PAM360
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus