CVE-2022-40300

CRITICALCVSS 9.8/10EPSS 99.27%

Last modified

CVE-2022-40300 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.. EPSS estimates a 99.27% chance of exploitation in the next 30 days.

Description

Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.27%

99.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ZohocorpManageengine Access Manager Plus4.0Build4000
ZohocorpManageengine Access Manager Plus4.1Build4100
ZohocorpManageengine Access Manager Plus4.2Build4200
ZohocorpManageengine Access Manager Plus4.3Build4300
ZohocorpManageengine Pam3604.0
ZohocorpManageengine Pam3604.1
ZohocorpManageengine Pam3604.5
ZohocorpManageengine Pam3605.0
ZohocorpManageengine Pam3605.1
ZohocorpManageengine Pam3605.2
ZohocorpManageengine Pam3605.3
ZohocorpManageengine Pam3605.4Build5400
ZohocorpManageengine Pam3605.5Build5500
ZohocorpManageengine Password Manager Pro4.6Build4600
ZohocorpManageengine Password Manager Pro4.7Build4700
ZohocorpManageengine Password Manager Pro4.8Build4803
ZohocorpManageengine Password Manager Pro5.0
ZohocorpManageengine Password Manager Pro5.1
ZohocorpManageengine Password Manager Pro5.2
ZohocorpManageengine Password Manager Pro5.3
ZohocorpManageengine Password Manager Pro5.4
ZohocorpManageengine Password Manager Pro6.0
ZohocorpManageengine Password Manager Pro6.1
ZohocorpManageengine Password Manager Pro6.2
ZohocorpManageengine Password Manager Pro6.3
ZohocorpManageengine Password Manager Pro6.4
ZohocorpManageengine Password Manager Pro6.5
ZohocorpManageengine Password Manager Pro6.6Build6600
ZohocorpManageengine Password Manager Pro6.7Build6700
ZohocorpManageengine Password Manager Pro6.8Build6800
ZohocorpManageengine Password Manager Pro6.9
ZohocorpManageengine Password Manager Pro7.0
ZohocorpManageengine Password Manager Pro7.1
ZohocorpManageengine Password Manager Pro7.5Build7500
ZohocorpManageengine Password Manager Pro7.6Build7600
ZohocorpManageengine Password Manager Pro8.0Build8000
ZohocorpManageengine Password Manager Pro8.1Build8100
ZohocorpManageengine Password Manager Pro8.2Build8200
ZohocorpManageengine Password Manager Pro8.3Build8300
ZohocorpManageengine Password Manager Pro8.4Build8041
ZohocorpManageengine Password Manager Pro8.5Build8500
ZohocorpManageengine Password Manager Pro8.6Build8600
ZohocorpManageengine Password Manager Pro8.7Build8700
ZohocorpManageengine Password Manager Pro9.0
ZohocorpManageengine Password Manager Pro9.1
ZohocorpManageengine Password Manager Pro9.2
ZohocorpManageengine Password Manager Pro9.3
ZohocorpManageengine Password Manager Pro9.4Build9400
ZohocorpManageengine Password Manager Pro9.5Build9500
ZohocorpManageengine Password Manager Pro9.6Build9600

Showing 50 of 63 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2022-40300?
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
How severe is CVE-2022-40300?
CVE-2022-40300 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 99.27% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40300?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-40300?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST