CVE-2022-43672

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
45.6%
top 2.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
CVEList
CVE-2022-43672: Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different softw2022-11-12
GHSA
GHSA-8f8x-4hjh-5xv4: Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different softw2022-11-12
CVE-2022-43672 (CRITICAL CVSS 9.8) | Zoho ManageEngine Password Manager | cvebase.io