CVE-2022-29081
28.04.2022, 20:15
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_access_manager_plus | 4.0:build4000 |
zohocorp | manageengine_access_manager_plus | 4.1:build4100 |
zohocorp | manageengine_access_manager_plus | 4.1:build4101 |
zohocorp | manageengine_access_manager_plus | 4.2:build4200 |
zohocorp | manageengine_access_manager_plus | 4.2:build4201 |
zohocorp | manageengine_access_manager_plus | 4.2:build4202 |
zohocorp | manageengine_access_manager_plus | 4.2:build4203 |
zohocorp | manageengine_access_manager_plus | 4.3:build4300 |
zohocorp | manageengine_access_manager_plus | 4.3:build4301 |
zohocorp | manageengine_pam360 | 4.0:build4001 |
zohocorp | manageengine_pam360 | 4.0:build4002 |
zohocorp | manageengine_pam360 | 4.1:build4100 |
zohocorp | manageengine_pam360 | 4.1:build4101 |
zohocorp | manageengine_pam360 | 4.5:build4500 |
zohocorp | manageengine_pam360 | 4.5:build4501 |
zohocorp | manageengine_pam360 | 5.0:build5000 |
zohocorp | manageengine_pam360 | 5.0:build5001 |
zohocorp | manageengine_pam360 | 5.0:build5002 |
zohocorp | manageengine_pam360 | 5.0:build5003 |
zohocorp | manageengine_pam360 | 5.0:build5004 |
zohocorp | manageengine_pam360 | 5.1:build5100 |
zohocorp | manageengine_pam360 | 5.2:build5200 |
zohocorp | manageengine_pam360 | 5.3:build5300 |
zohocorp | manageengine_pam360 | 5.3:build5301 |
zohocorp | manageengine_pam360 | 5.3:build5302 |
zohocorp | manageengine_pam360 | 5.4:build5400 |
zohocorp | manageengine_password_manager_pro | 10.1:build10103 |
zohocorp | manageengine_password_manager_pro | 10.1:build10104 |
zohocorp | manageengine_password_manager_pro | 10.2:build10200 |
zohocorp | manageengine_password_manager_pro | 10.3:build10300 |
zohocorp | manageengine_password_manager_pro | 10.3:build10301 |
zohocorp | manageengine_password_manager_pro | 10.3:build10302 |
zohocorp | manageengine_password_manager_pro | 10.4:build10400 |
zohocorp | manageengine_password_manager_pro | 10.4:build10401 |
zohocorp | manageengine_password_manager_pro | 10.4:build10402 |
zohocorp | manageengine_password_manager_pro | 11.1:11104 |
zohocorp | manageengine_password_manager_pro | 11.1:build_11101 |
zohocorp | manageengine_password_manager_pro | 11.1:build_11102 |
zohocorp | manageengine_password_manager_pro | 11.1:build_11103 |
zohocorp | manageengine_password_manager_pro | 11.2:build11200 |
zohocorp | manageengine_password_manager_pro | 11.2:build11201 |
zohocorp | manageengine_password_manager_pro | 11.3:build11300 |
zohocorp | manageengine_password_manager_pro | 11.3:build11301 |
zohocorp | manageengine_password_manager_pro | 12.0:build12000 |
zohocorp | manageengine_password_manager_pro | 12.0:build12001 |
zohocorp | manageengine_password_manager_pro | 12.0:build12002 |
zohocorp | manageengine_password_manager_pro | 12.0:build12003 |
zohocorp | manageengine_password_manager_pro | 12.0:build12004 |
zohocorp | manageengine_password_manager_pro | 12.0:build12005 |
zohocorp | manageengine_password_manager_pro | 12.0:build12006 |
𝑥
= Vulnerable software versions