CVE-2022-40300
Last modified
CVE-2022-40300 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.. EPSS estimates a 99.27% chance of exploitation in the next 30 days.
Description
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zohocorp | Manageengine Access Manager Plus | 4.0 | Build4000 |
| Zohocorp | Manageengine Access Manager Plus | 4.1 | Build4100 |
| Zohocorp | Manageengine Access Manager Plus | 4.2 | Build4200 |
| Zohocorp | Manageengine Access Manager Plus | 4.3 | Build4300 |
| Zohocorp | Manageengine Pam360 | 4.0 | — |
| Zohocorp | Manageengine Pam360 | 4.1 | — |
| Zohocorp | Manageengine Pam360 | 4.5 | — |
| Zohocorp | Manageengine Pam360 | 5.0 | — |
| Zohocorp | Manageengine Pam360 | 5.1 | — |
| Zohocorp | Manageengine Pam360 | 5.2 | — |
| Zohocorp | Manageengine Pam360 | 5.3 | — |
| Zohocorp | Manageengine Pam360 | 5.4 | Build5400 |
| Zohocorp | Manageengine Pam360 | 5.5 | Build5500 |
| Zohocorp | Manageengine Password Manager Pro | 4.6 | Build4600 |
| Zohocorp | Manageengine Password Manager Pro | 4.7 | Build4700 |
| Zohocorp | Manageengine Password Manager Pro | 4.8 | Build4803 |
| Zohocorp | Manageengine Password Manager Pro | 5.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 5.4 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.4 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.5 | — |
| Zohocorp | Manageengine Password Manager Pro | 6.6 | Build6600 |
| Zohocorp | Manageengine Password Manager Pro | 6.7 | Build6700 |
| Zohocorp | Manageengine Password Manager Pro | 6.8 | Build6800 |
| Zohocorp | Manageengine Password Manager Pro | 6.9 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 7.5 | Build7500 |
| Zohocorp | Manageengine Password Manager Pro | 7.6 | Build7600 |
| Zohocorp | Manageengine Password Manager Pro | 8.0 | Build8000 |
| Zohocorp | Manageengine Password Manager Pro | 8.1 | Build8100 |
| Zohocorp | Manageengine Password Manager Pro | 8.2 | Build8200 |
| Zohocorp | Manageengine Password Manager Pro | 8.3 | Build8300 |
| Zohocorp | Manageengine Password Manager Pro | 8.4 | Build8041 |
| Zohocorp | Manageengine Password Manager Pro | 8.5 | Build8500 |
| Zohocorp | Manageengine Password Manager Pro | 8.6 | Build8600 |
| Zohocorp | Manageengine Password Manager Pro | 8.7 | Build8700 |
| Zohocorp | Manageengine Password Manager Pro | 9.0 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.1 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.2 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.3 | — |
| Zohocorp | Manageengine Password Manager Pro | 9.4 | Build9400 |
| Zohocorp | Manageengine Password Manager Pro | 9.5 | Build9500 |
| Zohocorp | Manageengine Password Manager Pro | 9.6 | Build9600 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.htmlPatch, Vendor Advisory
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-40300?
How severe is CVE-2022-40300?
How do I fix CVE-2022-40300?
Are you affected by CVE-2022-40300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
