Record summary

CVE-2022-29081 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

manageengine_access_manager_plus

Browse Zoho / manageengine_access_manager_plus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALZoho ManageEngine - Access Control BypassCVSS 9.8

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

Impact

Attackers can bypass access controls on REST API endpoints, potentially leading to unauthorized data access or manipulation.

Remediation

Update to the latest versions of Access Manager Plus, Password Manager Pro, and PAM360 that address this issue.

WeaknessesCWE-22
Authors0xanis
Template tagscvecve2022zohomanageengineauth-bypassvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.title:"manageengine"

Source: ProjectDiscovery

References

3