CVE-2022-40300

CWE-89SQL Injection7 documents5 sources
Severity
9.8CRITICAL
EPSS
38.2%
top 2.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateDec 11

Description

Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mvcp-j3fp-64mm: Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 h2022-09-17
CVEList
CVE-2022-40300: Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 h2022-09-16

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Zoho ManageEngine Password Manager Pro SQL Injection (CVE-2022-40300)2025-12-11

🕵️Threat Intelligence

3
Trendmicro
SQL Injection in ManageEngine Privileged Access Management2022-11-23
Trendmicro
SQL Injection in ManageEngine Privileged Access Management2022-11-23
Trendmicro
SQL Injection in ManageEngine Privileged Access Management2022-11-23
CVE-2022-40300 (CRITICAL CVSS 9.8) | Zoho ManageEngine Password Manager | cvebase.io