CVE-2022-47523: SQL Injection
Published Jan 5, 2023
·Updated
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
Affected Software
14 affected components
Zohocorp ManageEngine Password Manager Pro<12.2
Zohocorp ManageEngine Password Manager Pro=12.2-build12200
ZohoCorp ManageEngine PAM360<5.8
ZohoCorp ManageEngine PAM360=5.8-build5800
Zohocorp Manageengine Access Manager Plus<4.3
Zohocorp Manageengine Access Manager Plus=4.3-build4300
Zohocorp Manageengine Access Manager Plus=4.3-build4301
Zohocorp Manageengine Access Manager Plus=4.3-build4302
Zohocorp Manageengine Access Manager Plus=4.3-build4303
Zohocorp Manageengine Access Manager Plus=4.3-build4304
Zohocorp Manageengine Access Manager Plus=4.3-build4305
Zohocorp Manageengine Access Manager Plus=4.3-build4306
Zohocorp Manageengine Access Manager Plus=4.3-build4307
Zohocorp Manageengine Access Manager Plus=4.3-build4308
Remediation
Event History
Jan 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-47523.
2
What is the severity of CVE-2022-47523?
The severity of CVE-2022-47523 is critical with a score of 9.8.
3
Which software products are affected by CVE-2022-47523?
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are affected by CVE-2022-47523.
4
What is the CWE category associated with CVE-2022-47523?
CVE-2022-47523 is associated with CWE category 89.
5
Where can I find more information about CVE-2022-47523?
You can find more information about CVE-2022-47523 at the following link: [https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html](https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html)