PT-2022-19401 · Zoho · Zoho Manageengine Access Manager Plus+2
Evan Grant
·
Published
2022-04-13
·
Updated
2025-12-05
·
CVE-2022-29081
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Access Manager Plus versions prior to 4302
Zoho ManageEngine Password Manager Pro versions prior to 12007
ManageEngine Privileged Access Manager 360 (PAM360) versions prior to 5401
Description
The software solutions Zoho ManageEngine Access Manager Plus, Zoho ManageEngine Password Manager Pro, and ManageEngine Privileged Access Manager 360 (PAM360) are affected by an improper path restriction issue. This can allow a remote attacker to bypass security restrictions and gain unauthorized access to protected information. The issue relates to access control bypass on several Rest API URLs, including those for
SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, and Synchronize, through the use of the '../RestAPI' substring.Recommendations
Zoho ManageEngine Access Manager Plus versions prior to 4302 should be updated.
Zoho ManageEngine Password Manager Pro versions prior to 12007 should be updated.
ManageEngine Privileged Access Manager 360 (PAM360) versions prior to 5401 should be updated.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pam 360
Password Manager Pro
Zoho Manageengine Access Manager Plus