First published: Sat Nov 12 2022(Updated: )
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Access Manager Plus | <4.3 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4300 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4301 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4302 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4303 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4304 | |
Zohocorp Manageengine Access Manager Plus | =4.3-build4305 | |
Zohocorp ManageEngine PAM360 | <5.7 | |
Zohocorp ManageEngine PAM360 | =5.7-build5700 | |
Zohocorp ManageEngine PAM360 | =5.7-build5710 | |
Zohocorp Manageengine Password Manager Pro | <12.1 | |
Zohocorp Manageengine Password Manager Pro | =12.1-build12100 | |
Zohocorp Manageengine Password Manager Pro | =12.1-build12101 | |
Zohocorp Manageengine Password Manager Pro | =12.1-build12110 | |
Zohocorp Manageengine Password Manager Pro | =12.1-build12120 | |
Zohocorp Manageengine Password Manager Pro | =12.1-build12121 | |
<4.3 | ||
=4.3-build4300 | ||
=4.3-build4301 | ||
=4.3-build4302 | ||
=4.3-build4303 | ||
=4.3-build4304 | ||
=4.3-build4305 | ||
<5.7 | ||
=5.7-build5700 | ||
=5.7-build5710 | ||
<12.1 | ||
=12.1-build12100 | ||
=12.1-build12101 | ||
=12.1-build12110 | ||
=12.1-build12120 | ||
=12.1-build12121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43671.
The severity of CVE-2022-43671 is critical.
Zoho ManageEngine Password Manager Pro before 12.1.22, PAM360 before 5.7.11, and Access Manager Plus before 4.3.6 are affected by CVE-2022-43671.
CVE-2022-43671 allows SQL Injection through Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus.
You can find more information about CVE-2022-43671 at this link: [CVE-2022-43671](https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-43671.html).