Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Zoho Manageengine Access Manager Plus | — | Upgrade Zoho ManageEngine Access Manager Plus to 4303. | Jan 20, 2023 | Jul 19, 2022 |
| Zoho Manageengine Pam360 | — | Upgrade Zoho ManageEngine PAM360 to the latest version | Jul 2, 2025 | Jun 23, 2022 |
| Zoho Manageengine Password Manager Pro | — | Upgrade Zoho ManageEngine Password Manager Pro to 12101. | Jan 20, 2023 | Jul 19, 2022 |
| Zoho Manageengine Passwordmanager Pro | — | Upgrade Zoho ManageEngine PasswordManager Pro to the latest version | Dec 23, 2024 | Jun 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub