CVE-2022-29081
Zoho manageengine_access_manager_plus Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2022-29081 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
manageengine_access_manager_plusBrowse Zoho / manageengine_access_manager_plus | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALZoho ManageEngine - Access Control BypassCVSS 9.8
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Impact
Attackers can bypass access controls on REST API endpoints, potentially leading to unauthorized data access or manipulation.
Remediation
Update to the latest versions of Access Manager Plus, Password Manager Pro, and PAM360 that address this issue.
Source: ProjectDiscovery