Description


Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

Related CPE's


a

zohocorp

manageengine_access_manager_plus

7

a

zohocorp

manageengine_pam360

3

a

zohocorp

manageengine_password_manager_pro

6

Weaknesses



CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-11-12T04:15:10.290

2 years ago

Last modified

2022-11-16T23:13:48.827

2 years ago