Severity
8.2HIGH
EPSS
1.1%
top 21.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateJul 19

Description

ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 3.9 | Impact: 4.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vcmg-67gw-xr96: ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serve2022-07-19
CVEList
CVE-2022-35404: ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serve2022-07-18
CVE-2022-35404 (HIGH CVSS 8.2) | ManageEngine Password Manager Pro 1 | cvebase.io