PT-2022-4859 · Zoho · Zoho Manageengine Access Manager Plus+2

Vinicius

·

Published

2022-07-19

·

Updated

2025-10-31

·

CVE-2022-35405

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Password Manager Pro versions prior to 12101 Zoho ManageEngine PAM360 versions prior to 5510 Zoho ManageEngine Access Manager Plus versions prior to 4303
Description The issue is related to a deserialization mechanism flaw in the xmlrpc component of Zoho ManageEngine Password Manager Pro and Zoho ManageEngine Access Manager Plus, allowing an unauthenticated remote attacker to execute arbitrary code.
Recommendations For Zoho ManageEngine Password Manager Pro versions prior to 12101, update to version 12101 or later. For Zoho ManageEngine PAM360 versions prior to 5510, update to version 5510 or later. For Zoho ManageEngine Access Manager Plus versions prior to 4303, update to version 4303 or later. As a temporary workaround, consider restricting access to the xmlrpc component until a patch is applied.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-05983
CVE-2022-35405

Affected Products

Zoho Manageengine Access Manager Plus
Zoho Manageengine Pam360
Manageengine Password Manager Pro