CVE-2021-44525
CRITICALManageEngine PAM360 < 5303 - Unauthenticated Authentication Bypass via Filter Bypass
Title source: llmDescription
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
References (1)
Core 1
Core References
Scores
CVSS v3
9.8
EPSS
0.0057
EPSS Percentile
68.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (7)
zohocorp/manageengine_pam360
4.0 (3 CPE variants)
zohocorp/manageengine_pam360
4.1 (3 CPE variants)
zohocorp/manageengine_pam360
4.5 (3 CPE variants)
zohocorp/manageengine_pam360
5.0 (6 CPE variants)
zohocorp/manageengine_pam360
5.1 (2 CPE variants)
zohocorp/manageengine_pam360
5.2 (2 CPE variants)
zohocorp/manageengine_pam360
5.3 (4 CPE variants)
Published
Dec 20, 2021
Tracked Since
Feb 18, 2026