CVE-2022-43671

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
zohocorpmanageengine_access_manager_plus
𝑥
< 4.3
zohocorpmanageengine_access_manager_plus
4.3:build4300
zohocorpmanageengine_access_manager_plus
4.3:build4301
zohocorpmanageengine_access_manager_plus
4.3:build4302
zohocorpmanageengine_access_manager_plus
4.3:build4303
zohocorpmanageengine_access_manager_plus
4.3:build4304
zohocorpmanageengine_access_manager_plus
4.3:build4305
zohocorpmanageengine_pam360
𝑥
< 5.7
zohocorpmanageengine_pam360
5.7:build5700
zohocorpmanageengine_pam360
5.7:build5710
zohocorpmanageengine_password_manager_pro
𝑥
< 12.1
zohocorpmanageengine_password_manager_pro
12.1:build12100
zohocorpmanageengine_password_manager_pro
12.1:build12101
zohocorpmanageengine_password_manager_pro
12.1:build12110
zohocorpmanageengine_password_manager_pro
12.1:build12120
zohocorpmanageengine_password_manager_pro
12.1:build12121
𝑥
= Vulnerable software versions