Description


Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

Related CPE's


a

zohocorp

manageengine_access_manager_plus

7

a

zohocorp

manageengine_pam360

3

a

zohocorp

manageengine_password_manager_pro

6

Weaknesses



CWE-89

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-12T03:15:10.290Z

3 years ago

Last modified

2025-05-01T12:15:29.797Z

10 months ago