CVE-2022-43672: SQL Injection
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43672?
CVE-2022-43672 is a vulnerability that allows SQL Injection in Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus.
What is the severity of CVE-2022-43672?
CVE-2022-43672 has a severity rating of 9.8 out of 10, which is classified as critical.
How does CVE-2022-43672 affect Zoho ManageEngine Password Manager Pro?
CVE-2022-43672 affects Zoho ManageEngine Password Manager Pro versions before 12.1. It allows SQL Injection in the software.
How does CVE-2022-43672 affect PAM360?
CVE-2022-43672 affects PAM360 versions before 5.7. It allows SQL Injection in the software.
How does CVE-2022-43672 affect Access Manager Plus?
CVE-2022-43672 affects Access Manager Plus versions before 4.3. It allows SQL Injection in the software.
How can I fix CVE-2022-43672 in Zoho ManageEngine Password Manager Pro?
To fix CVE-2022-43672 in Zoho ManageEngine Password Manager Pro, you should upgrade to version 12.1 or later.
How can I fix CVE-2022-43672 in PAM360?
To fix CVE-2022-43672 in PAM360, you should upgrade to version 5.7 or later.
How can I fix CVE-2022-43672 in Access Manager Plus?
To fix CVE-2022-43672 in Access Manager Plus, you should upgrade to version 4.3 or later.