Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Access Manager Plus
APPZohocorp4.3< 4.3Zohocorp Manageengine Pam360
APPZohocorp5.8< 5.8Zohocorp Manageengine Password Manager Pro
APPZohocorp12.2< 12.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLiXSS
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2022-35405CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu w Zoho ManageEngine Password Manager Pro i PAM360
CVE-2022-43671CRITICAL9.8PL ✓same product
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus
CVE-2022-43672CRITICAL9.8PL ✓same product
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus
CVE-2022-40300CRITICAL9.8PL ✓same product
SQL Injection w Zoho ManageEngine Password Manager Pro, PAM360 i Access Manager Plus