9.8
CVE-2022-29081
- EPSS 83.54%
- Veröffentlicht 28.04.2022 20:15:08
- Zuletzt bearbeitet 06.11.2025 22:24:29
- Erkennungen
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Access Manager Plus Version 4.0 Update build4000
Zohocorp ≫ Manageengine Access Manager Plus Version 4.1 Update build4100
Zohocorp ≫ Manageengine Access Manager Plus Version 4.1 Update build4101
Zohocorp ≫ Manageengine Access Manager Plus Version 4.2 Update build4200
Zohocorp ≫ Manageengine Access Manager Plus Version 4.2 Update build4201
Zohocorp ≫ Manageengine Access Manager Plus Version 4.2 Update build4202
Zohocorp ≫ Manageengine Access Manager Plus Version 4.2 Update build4203
Zohocorp ≫ Manageengine Access Manager Plus Version 4.3 Update build4300
Zohocorp ≫ Manageengine Access Manager Plus Version 4.3 Update build4301
Zohocorp ≫ Manageengine Pam360 Version 4.0 Update build4001
Zohocorp ≫ Manageengine Pam360 Version 4.0 Update build4002
Zohocorp ≫ Manageengine Pam360 Version 4.1 Update build4100
Zohocorp ≫ Manageengine Pam360 Version 4.1 Update build4101
Zohocorp ≫ Manageengine Pam360 Version 4.5 Update build4500
Zohocorp ≫ Manageengine Pam360 Version 4.5 Update build4501
Zohocorp ≫ Manageengine Pam360 Version 5.0 Update build5000
Zohocorp ≫ Manageengine Pam360 Version 5.0 Update build5001
Zohocorp ≫ Manageengine Pam360 Version 5.0 Update build5002
Zohocorp ≫ Manageengine Pam360 Version 5.0 Update build5003
Zohocorp ≫ Manageengine Pam360 Version 5.0 Update build5004
Zohocorp ≫ Manageengine Pam360 Version 5.1 Update build5100
Zohocorp ≫ Manageengine Pam360 Version 5.2 Update build5200
Zohocorp ≫ Manageengine Pam360 Version 5.3 Update build5300
Zohocorp ≫ Manageengine Pam360 Version 5.3 Update build5301
Zohocorp ≫ Manageengine Pam360 Version 5.3 Update build5302
Zohocorp ≫ Manageengine Pam360 Version 5.4 Update build5400
Zohocorp ≫ Manageengine Password Manager Pro Version 10.1 Update build10103
Zohocorp ≫ Manageengine Password Manager Pro Version 10.1 Update build10104
Zohocorp ≫ Manageengine Password Manager Pro Version 10.2 Update build10200
Zohocorp ≫ Manageengine Password Manager Pro Version 10.3 Update build10300
Zohocorp ≫ Manageengine Password Manager Pro Version 10.3 Update build10301
Zohocorp ≫ Manageengine Password Manager Pro Version 10.3 Update build10302
Zohocorp ≫ Manageengine Password Manager Pro Version 10.4 Update build10400
Zohocorp ≫ Manageengine Password Manager Pro Version 10.4 Update build10401
Zohocorp ≫ Manageengine Password Manager Pro Version 10.4 Update build10402
Zohocorp ≫ Manageengine Password Manager Pro Version 11.1 Update 11104
Zohocorp ≫ Manageengine Password Manager Pro Version 11.1 Update build_11101
Zohocorp ≫ Manageengine Password Manager Pro Version 11.1 Update build_11102
Zohocorp ≫ Manageengine Password Manager Pro Version 11.1 Update build_11103
Zohocorp ≫ Manageengine Password Manager Pro Version 11.2 Update build11200
Zohocorp ≫ Manageengine Password Manager Pro Version 11.2 Update build11201
Zohocorp ≫ Manageengine Password Manager Pro Version 11.3 Update build11300
Zohocorp ≫ Manageengine Password Manager Pro Version 11.3 Update build11301
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12000
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12001
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12002
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12003
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12004
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12005
Zohocorp ≫ Manageengine Password Manager Pro Version 12.0 Update build12006
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 83.54% | 0.997 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://www.manageengine.com/privileged-session-management/advisory/cve-2022-29081.html
https://www.tenable.com/security/research/tra-2022-14