9.8

CVE-2022-29081

Exploit

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Access Manager Plus Version4.0 Updatebuild4000
ZohocorpManageengine Access Manager Plus Version4.1 Updatebuild4100
ZohocorpManageengine Access Manager Plus Version4.1 Updatebuild4101
ZohocorpManageengine Access Manager Plus Version4.2 Updatebuild4200
ZohocorpManageengine Access Manager Plus Version4.2 Updatebuild4201
ZohocorpManageengine Access Manager Plus Version4.2 Updatebuild4202
ZohocorpManageengine Access Manager Plus Version4.2 Updatebuild4203
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4300
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4301
ZohocorpManageengine Pam360 Version4.0 Updatebuild4001
ZohocorpManageengine Pam360 Version4.0 Updatebuild4002
ZohocorpManageengine Pam360 Version4.1 Updatebuild4100
ZohocorpManageengine Pam360 Version4.1 Updatebuild4101
ZohocorpManageengine Pam360 Version4.5 Updatebuild4500
ZohocorpManageengine Pam360 Version4.5 Updatebuild4501
ZohocorpManageengine Pam360 Version5.0 Updatebuild5000
ZohocorpManageengine Pam360 Version5.0 Updatebuild5001
ZohocorpManageengine Pam360 Version5.0 Updatebuild5002
ZohocorpManageengine Pam360 Version5.0 Updatebuild5003
ZohocorpManageengine Pam360 Version5.0 Updatebuild5004
ZohocorpManageengine Pam360 Version5.1 Updatebuild5100
ZohocorpManageengine Pam360 Version5.2 Updatebuild5200
ZohocorpManageengine Pam360 Version5.3 Updatebuild5300
ZohocorpManageengine Pam360 Version5.3 Updatebuild5301
ZohocorpManageengine Pam360 Version5.3 Updatebuild5302
ZohocorpManageengine Pam360 Version5.4 Updatebuild5400
ZohocorpManageengine Password Manager Pro Version10.1 Updatebuild10103
ZohocorpManageengine Password Manager Pro Version10.1 Updatebuild10104
ZohocorpManageengine Password Manager Pro Version10.2 Updatebuild10200
ZohocorpManageengine Password Manager Pro Version10.3 Updatebuild10300
ZohocorpManageengine Password Manager Pro Version10.3 Updatebuild10301
ZohocorpManageengine Password Manager Pro Version10.3 Updatebuild10302
ZohocorpManageengine Password Manager Pro Version10.4 Updatebuild10400
ZohocorpManageengine Password Manager Pro Version10.4 Updatebuild10401
ZohocorpManageengine Password Manager Pro Version10.4 Updatebuild10402
ZohocorpManageengine Password Manager Pro Version11.1 Update11104
ZohocorpManageengine Password Manager Pro Version11.1 Updatebuild_11101
ZohocorpManageengine Password Manager Pro Version11.1 Updatebuild_11102
ZohocorpManageengine Password Manager Pro Version11.1 Updatebuild_11103
ZohocorpManageengine Password Manager Pro Version11.2 Updatebuild11200
ZohocorpManageengine Password Manager Pro Version11.2 Updatebuild11201
ZohocorpManageengine Password Manager Pro Version11.3 Updatebuild11300
ZohocorpManageengine Password Manager Pro Version11.3 Updatebuild11301
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12000
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12001
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12002
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12003
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12004
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12005
ZohocorpManageengine Password Manager Pro Version12.0 Updatebuild12006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.27% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.