CVE-2022-35405: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
Other sources
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-35405?
CVE-2022-35405 is a vulnerability in Zoho ManageEngine Password Manager Pro and PAM360 that allows unauthenticated remote code execution.
What is the severity of CVE-2022-35405?
CVE-2022-35405 has a severity rating of 9.8 out of 10, which is considered critical.
Which Zoho products are affected by CVE-2022-35405?
CVE-2022-35405 affects Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus.
How can an attacker exploit CVE-2022-35405?
An attacker can exploit CVE-2022-35405 by sending a specially crafted request to the vulnerable Zoho ManageEngine products, allowing them to execute remote code without authentication.
Where can I find more information about CVE-2022-35405?
You can find more information about CVE-2022-35405 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.html), [ManageEngine Advisory](https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html).