CVE-2022-40300
Last modified
CVE-2022-40300 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.. EPSS estimates a 99.27% chance of exploitation in the next 30 days.
Description
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zohocorp | Manageengine Access Manager Plus | 4.0 | Build4000 |
| Zohocorp | Manageengine Access Manager Plus | 4.1 | Build4100 |
| Zohocorp | Manageengine Access Manager Plus | 4.2 | Build4200 |
| Zohocorp | Manageengine Access Manager Plus | 4.3 | Build4300 |
| Zohocorp | Manageengine Pam360 | 4.0 | — |
| Zohocorp | Manageengine Pam360 | 4.1 | — |
| Zohocorp | Manageengine Pam360 | 4.5 | — |
| Zohocorp | Manageengine Pam360 | 5.0 | — |
| Zohocorp | Manageengine Pam360 | 5.1 | — |
| Zohocorp | Manageengine Pam360 | 5.2 | — |
| Zohocorp | Manageengine Pam360 | 5.3 | — |
| Zohocorp | Manageengine Pam360 | 5.4 | Build5400 |
| Zohocorp | Manageengine Pam360 | 5.5 | Build5500 |
| Zohocorp | Manageengine Password Manager Pro | 4.6 | Build4600 |
| Zohocorp | Manageengine Password Manager Pro | 4.7 | Build4700 |
| Zohocorp | Manageengine Password Manager Pro | 4.8 | Build4803 |
| Zohocorp | Manageengine Password Manager Pro | 5.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.4 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.4 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.5 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.6 | Build6600 |
| Zohocorp | Manageengine Password Manager Pro | 6.7 | Build6700 |
| Zohocorp | Manageengine Password Manager Pro | 6.8 | Build6800 |
| Zohocorp | Manageengine Password Manager Pro | 6.9 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.5 | Build7500 |
| Zohocorp | Manageengine Password Manager Pro | 7.6 | Build7600 |
| Zohocorp | Manageengine Password Manager Pro | 8.0 | Build8000 |
| Zohocorp | Manageengine Password Manager Pro | 8.1 | Build8100 |
| Zohocorp | Manageengine Password Manager Pro | 8.2 | Build8200 |
| Zohocorp | Manageengine Password Manager Pro | 8.3 | Build8300 |
| Zohocorp | Manageengine Password Manager Pro | 8.4 | Build8041 |
| Zohocorp | Manageengine Password Manager Pro | 8.5 | Build8500 |
| Zohocorp | Manageengine Password Manager Pro | 8.6 | Build8600 |
| Zohocorp | Manageengine Password Manager Pro | 8.7 | Build8700 |
| Zohocorp | Manageengine Password Manager Pro | 9.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.4 | Build9400 |
| Zohocorp | Manageengine Password Manager Pro | 9.5 | Build9500 |
| Zohocorp | Manageengine Password Manager Pro | 9.6 | Build9600 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.htmlPatch, Vendor Advisory
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-40300?
How severe is CVE-2022-40300?
How do I fix CVE-2022-40300?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40295The application was vulnerable to an authenticated informati…4.9
- CVE-2022-40296 The application was vulnerable to a Server-Side Request For…9.8
- CVE-2022-40297UBports Ubuntu Touch 16.04 allows the screen-unlock passcode…7.8
- CVE-2022-40298Crestron AirMedia for Windows before 5.5.1.84 has insecure i…8.8
- CVE-2022-40299In Singular before 4.3.1, a predictable /tmp pathname is use…7.8
- CVE-2022-4030The Simple:Press plugin for WordPress is vulnerable to Path …8.1
- CVE-2022-40302An issue was discovered in bgpd in FRRouting (FRR) through 8…6.5
- CVE-2022-40303An issue was discovered in libxml2 before 2.10.3. When parsi…7.5
- CVE-2022-40304An issue was discovered in libxml2 before 2.10.3. Certain in…7.8
- CVE-2022-40305A Server-Side Request Forgery issue in Canto Cumulus through…9.8
- CVE-2022-40306The login form /Login in ECi Printanista Hub (formerly FMAud…5.9
- CVE-2022-40307An issue was discovered in the Linux kernel through 5.19.8. …4.7
Are you affected by CVE-2022-40300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
