CVE-2024-5546

HIGHCVSS 8.8/10EPSS 3.04%

Last modified

CVE-2024-5546 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.. EPSS estimates a 3.04% chance of exploitation in the next 30 days.

Description

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
3.04%

85.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ZohocorpManageengine Pam3604.0
ZohocorpManageengine Pam3604.1
ZohocorpManageengine Pam3604.5
ZohocorpManageengine Pam3605.0
ZohocorpManageengine Pam3605.1
ZohocorpManageengine Pam3605.2
ZohocorpManageengine Pam3605.3
ZohocorpManageengine Pam3605.4Build5400
ZohocorpManageengine Pam3605.5Build5500
ZohocorpManageengine Pam3605.7Build5700
ZohocorpManageengine Pam3605.8Build5800
ZohocorpManageengine Pam3605.9Build5900
ZohocorpManageengine Pam3606.0Build6000
ZohocorpManageengine Pam3606.1Build6100
ZohocorpManageengine Pam3606.2Build6200
ZohocorpManageengine Pam3606.3Build6300
ZohocorpManageengine Pam3606.4Build6400
ZohocorpManageengine Pam3606.5Build6500
ZohocorpManageengine Pam3606.6Build6600
ZohocorpManageengine Pam3606.7Build6700
ZohocorpManageengine Pam3607.0Build7000
ZohocorpManageengine Password Manager Pro6.0Build6002
ZohocorpManageengine Password Manager Pro6.1Build6104
ZohocorpManageengine Password Manager Pro6.2Build6201
ZohocorpManageengine Password Manager Pro6.4Build6401
ZohocorpManageengine Password Manager Pro6.5Build6503
ZohocorpManageengine Password Manager Pro6.6Build6600
ZohocorpManageengine Password Manager Pro6.7Build6700
ZohocorpManageengine Password Manager Pro6.8Build6800
ZohocorpManageengine Password Manager Pro6.9Build6900
ZohocorpManageengine Password Manager Pro7.0Build7000
ZohocorpManageengine Password Manager Pro7.1Build7100
ZohocorpManageengine Password Manager Pro7.5Build7500
ZohocorpManageengine Password Manager Pro7.6Build7600
ZohocorpManageengine Password Manager Pro8.0Build8000
ZohocorpManageengine Password Manager Pro8.1Build8100
ZohocorpManageengine Password Manager Pro8.2Build8200
ZohocorpManageengine Password Manager Pro8.3Build8300
ZohocorpManageengine Password Manager Pro8.4Build8041
ZohocorpManageengine Password Manager Pro8.5Build8500
ZohocorpManageengine Password Manager Pro8.6Build8600
ZohocorpManageengine Password Manager Pro8.7Build8700
ZohocorpManageengine Password Manager Pro9.0Build9000
ZohocorpManageengine Password Manager Pro9.1Build9100
ZohocorpManageengine Password Manager Pro9.2Build9200
ZohocorpManageengine Password Manager Pro9.3Build9300
ZohocorpManageengine Password Manager Pro9.4Build9400
ZohocorpManageengine Password Manager Pro9.5Build9500
ZohocorpManageengine Password Manager Pro9.6Build9600
ZohocorpManageengine Password Manager Pro9.7Build9700

Showing 50 of 67 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-5546?
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
How severe is CVE-2024-5546?
CVE-2024-5546 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 3.04% probability of exploitation in the next 30 days.
How do I fix CVE-2024-5546?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-5546?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST