CVE-2022-29081

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
zohocorpmanageengine_access_manager_plus
4.0:build4000
zohocorpmanageengine_access_manager_plus
4.1:build4100
zohocorpmanageengine_access_manager_plus
4.1:build4101
zohocorpmanageengine_access_manager_plus
4.2:build4200
zohocorpmanageengine_access_manager_plus
4.2:build4201
zohocorpmanageengine_access_manager_plus
4.2:build4202
zohocorpmanageengine_access_manager_plus
4.2:build4203
zohocorpmanageengine_access_manager_plus
4.3:build4300
zohocorpmanageengine_access_manager_plus
4.3:build4301
zohocorpmanageengine_pam360
4.0:build4001
zohocorpmanageengine_pam360
4.0:build4002
zohocorpmanageengine_pam360
4.1:build4100
zohocorpmanageengine_pam360
4.1:build4101
zohocorpmanageengine_pam360
4.5:build4500
zohocorpmanageengine_pam360
4.5:build4501
zohocorpmanageengine_pam360
5.0:build5000
zohocorpmanageengine_pam360
5.0:build5001
zohocorpmanageengine_pam360
5.0:build5002
zohocorpmanageengine_pam360
5.0:build5003
zohocorpmanageengine_pam360
5.0:build5004
zohocorpmanageengine_pam360
5.1:build5100
zohocorpmanageengine_pam360
5.2:build5200
zohocorpmanageengine_pam360
5.3:build5300
zohocorpmanageengine_pam360
5.3:build5301
zohocorpmanageengine_pam360
5.3:build5302
zohocorpmanageengine_pam360
5.4:build5400
zohocorpmanageengine_password_manager_pro
10.1:build10103
zohocorpmanageengine_password_manager_pro
10.1:build10104
zohocorpmanageengine_password_manager_pro
10.2:build10200
zohocorpmanageengine_password_manager_pro
10.3:build10300
zohocorpmanageengine_password_manager_pro
10.3:build10301
zohocorpmanageengine_password_manager_pro
10.3:build10302
zohocorpmanageengine_password_manager_pro
10.4:build10400
zohocorpmanageengine_password_manager_pro
10.4:build10401
zohocorpmanageengine_password_manager_pro
10.4:build10402
zohocorpmanageengine_password_manager_pro
11.1:11104
zohocorpmanageengine_password_manager_pro
11.1:build_11101
zohocorpmanageengine_password_manager_pro
11.1:build_11102
zohocorpmanageengine_password_manager_pro
11.1:build_11103
zohocorpmanageengine_password_manager_pro
11.2:build11200
zohocorpmanageengine_password_manager_pro
11.2:build11201
zohocorpmanageengine_password_manager_pro
11.3:build11300
zohocorpmanageengine_password_manager_pro
11.3:build11301
zohocorpmanageengine_password_manager_pro
12.0:build12000
zohocorpmanageengine_password_manager_pro
12.0:build12001
zohocorpmanageengine_password_manager_pro
12.0:build12002
zohocorpmanageengine_password_manager_pro
12.0:build12003
zohocorpmanageengine_password_manager_pro
12.0:build12004
zohocorpmanageengine_password_manager_pro
12.0:build12005
zohocorpmanageengine_password_manager_pro
12.0:build12006
𝑥
= Vulnerable software versions