← Back

CVE-2022-29081

Published: Apr 28, 2022Modified: Nov 6, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

Affected (50)

3 products
Manageengine Access Manager Plus
Manageengine Pam360
Manageengine Password Manager Pro
Configuration A
50 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Version 4.0 build4000
Version 4.1 build4100
Version 4.1 build4101
Version 4.2 build4200
Version 4.2 build4201
Version 4.2 build4202
Version 4.2 build4203
Version 4.3 build4300
Version 4.3 build4301
Zohocorp
Version 4.0 build4001
Version 4.0 build4002
Version 4.1 build4100
Version 4.1 build4101
Version 4.5 build4500
Version 4.5 build4501
Version 5.0 build5000
Version 5.0 build5001
Version 5.0 build5002
Version 5.0 build5003
Version 5.0 build5004
Version 5.1 build5100
Version 5.2 build5200
Version 5.3 build5300
Version 5.3 build5301
Version 5.3 build5302
Version 5.4 build5400
Zohocorp
Version 10.1 build10103
Version 10.1 build10104
Version 10.2 build10200
Version 10.3 build10300
Version 10.3 build10301
Version 10.3 build10302
Version 10.4 build10400
Version 10.4 build10401
Version 10.4 build10402
Version 11.1 11104
Version 11.1 build_11101
Version 11.1 build_11102
Version 11.1 build_11103
Version 11.2 build11200
Version 11.2 build11201
Version 11.3 build11300
Version 11.3 build11301
Version 12.0 build12000
Version 12.0 build12001
Version 12.0 build12002
Version 12.0 build12003
Version 12.0 build12004
Version 12.0 build12005
Version 12.0 build12006

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.