CVE-2025-11669: Broken Access Control
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11669?
CVE-2025-11669 is classified as a high severity vulnerability due to its impact on access control.
How do I fix CVE-2025-11669?
To address CVE-2025-11669, upgrade to Zohocorp ManageEngine PAM360 version 8202 or later, Password Manager Pro version 13221 or later, or Access Manager Plus version 4401 or later.
What systems are affected by CVE-2025-11669?
CVE-2025-11669 affects Zohocorp ManageEngine PAM360 versions before 8202, Password Manager Pro versions before 13221, and Access Manager Plus versions prior to 4401.
What is the nature of the vulnerability CVE-2025-11669?
CVE-2025-11669 involves a broken access control issue in the initiate remote session functionality.
Who is the vendor for CVE-2025-11669?
The vendor for CVE-2025-11669 is Zohocorp, which develops ManageEngine products.