Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Zoho Manageengine Access Manager Plus | zoho-manageengine-access-manager-plus-upgrade-4303 | Jan 20, 2023 | Jul 19, 2022 | |
| Zoho Manageengine Pam360 | zoho-manageengine-pam360-upgrade-latest | Jul 2, 2025 | Jun 23, 2022 | |
| Zoho Manageengine Password Manager Pro | zoho-manageengine-password-manager-pro-upgrade-12101 | Jan 20, 2023 | Jul 19, 2022 | |
| Zoho Manageengine Passwordmanager Pro | zoho-manageengine-passwordmanager-pro-upgrade-latest | Dec 23, 2024 | Jun 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub