First published: Thu Apr 28 2022(Updated: )
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Access Manager Plus | =4.0-build4000 | |
Zohocorp Manageengine Access Manager Plus | =4.1-build4100 | |
Zohocorp Manageengine Access Manager Plus | =4.1-build4101 | |
Zohocorp Manageengine Access Manager Plus | =4.2-build4200 | |
Zohocorp Manageengine Access Manager Plus | =4.2-build4201 | |
Zohocorp Manageengine Access Manager Plus | =4.2-build4202 | |
Zohocorp Manageengine Access Manager Plus | =4.2-build4203 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4300 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4301 | |
Zohocorp ManageEngine PAM360 | =4.0-build4001 | |
Zohocorp ManageEngine PAM360 | =4.0-build4002 | |
Zohocorp ManageEngine PAM360 | =4.1-build4100 | |
Zohocorp ManageEngine PAM360 | =4.1-build4101 | |
Zohocorp ManageEngine PAM360 | =4.5-build4500 | |
Zohocorp ManageEngine PAM360 | =4.5-build4501 | |
Zohocorp ManageEngine PAM360 | =5.0-build5000 | |
Zohocorp ManageEngine PAM360 | =5.0-build5001 | |
Zohocorp ManageEngine PAM360 | =5.0-build5002 | |
Zohocorp ManageEngine PAM360 | =5.0-build5003 | |
Zohocorp ManageEngine PAM360 | =5.0-build5004 | |
Zohocorp ManageEngine PAM360 | =5.1-build5100 | |
Zohocorp ManageEngine PAM360 | =5.2-build5200 | |
Zohocorp ManageEngine PAM360 | =5.3-build5300 | |
Zohocorp ManageEngine PAM360 | =5.3-build5301 | |
Zohocorp ManageEngine PAM360 | =5.3-build5302 | |
Zohocorp ManageEngine PAM360 | =5.4-build5400 | |
Zohocorp Manageengine Password Manager Pro | =10.1-build10103 | |
Zohocorp Manageengine Password Manager Pro | =10.1-build10104 | |
Zohocorp Manageengine Password Manager Pro | =10.2-build10200 | |
Zohocorp Manageengine Password Manager Pro | =10.3-build10300 | |
Zohocorp Manageengine Password Manager Pro | =10.3-build10301 | |
Zohocorp Manageengine Password Manager Pro | =10.3-build10302 | |
Zohocorp Manageengine Password Manager Pro | =10.4-build10400 | |
Zohocorp Manageengine Password Manager Pro | =10.4-build10401 | |
Zohocorp Manageengine Password Manager Pro | =10.4-build10402 | |
Zohocorp Manageengine Password Manager Pro | =11.1-11104 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11101 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11102 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11103 | |
Zohocorp Manageengine Password Manager Pro | =11.2-11200 | |
Zohocorp Manageengine Password Manager Pro | =11.2-11201 | |
Zohocorp Manageengine Password Manager Pro | =11.3-build11300 | |
Zohocorp Manageengine Password Manager Pro | =11.3-build11301 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12000 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12001 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12002 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12003 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12004 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12005 | |
Zohocorp Manageengine Password Manager Pro | =12.0-build12006 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.