PT-2022-19401 · Zoho · Zoho Manageengine Access Manager Plus+2

Evan Grant

·

Published

2022-04-13

·

Updated

2025-12-05

·

CVE-2022-29081

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Access Manager Plus versions prior to 4302 Zoho ManageEngine Password Manager Pro versions prior to 12007 ManageEngine Privileged Access Manager 360 (PAM360) versions prior to 5401
Description The software solutions Zoho ManageEngine Access Manager Plus, Zoho ManageEngine Password Manager Pro, and ManageEngine Privileged Access Manager 360 (PAM360) are affected by an improper path restriction issue. This can allow a remote attacker to bypass security restrictions and gain unauthorized access to protected information. The issue relates to access control bypass on several Rest API URLs, including those for SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, and Synchronize, through the use of the '../RestAPI' substring.
Recommendations Zoho ManageEngine Access Manager Plus versions prior to 4302 should be updated. Zoho ManageEngine Password Manager Pro versions prior to 12007 should be updated. ManageEngine Privileged Access Manager 360 (PAM360) versions prior to 5401 should be updated.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-14638
CVE-2022-29081

Affected Products

Pam 360
Password Manager Pro
Zoho Manageengine Access Manager Plus