PT-2022-25337 · Zoho · Zoho Manageengine Access Manager Plus+2

Published

2022-09-16

·

Updated

2025-11-06

·

CVE-2022-40300

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Password Manager Pro versions 12120 through 12120 Zoho ManageEngine PAM360 versions 5550 through 5550 Zoho ManageEngine Access Manager Plus versions 4304 through 4304
Description The issue involves multiple SQL injection vulnerabilities.
Recommendations For Zoho ManageEngine Password Manager Pro version 12120, update to version 12121 or later. For Zoho ManageEngine PAM360 version 5550, update to version 5600 or later. For Zoho ManageEngine Access Manager Plus version 4304, update to version 4305 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-40300

Affected Products

Zoho Manageengine Access Manager Plus
Zoho Manageengine Pam360
Manageengine Password Manager Pro