Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
2022-07-19T15:15:08.680
2025-03-27T13:59:59.140
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_access_manager_plus | < 4.3 | Yes |
Application | zohocorp | manageengine_access_manager_plus | 4.3 | Yes |
Application | zohocorp | manageengine_access_manager_plus | 4.3 | Yes |
Application | zohocorp | manageengine_access_manager_plus | 4.3 | Yes |
Application | zohocorp | manageengine_pam360 | < 5.5 | Yes |
Application | zohocorp | manageengine_pam360 | 5.5 | Yes |
Application | zohocorp | manageengine_password_manager_pro | < 12.1 | Yes |
Application | zohocorp | manageengine_password_manager_pro | 12.1 | Yes |