Lucene search

K
cve[email protected]CVE-2022-29081
HistoryApr 28, 2022 - 8:15 p.m.

CVE-2022-29081

2022-04-2820:15:08
CWE-22
web.nvd.nist.gov
533
2
cve-2022-29081
zoho
manageengine
access manager plus
password manager pro
pam360
vulnerability
access-control bypass
rest api
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.517 Medium

EPSS

Percentile

97.6%

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the …/RestAPI substring.

Affected configurations

NVD
Node
zohocorpmanageengine_access_manager_plusMatch4.0build4000
OR
zohocorpmanageengine_access_manager_plusMatch4.1build4100
OR
zohocorpmanageengine_access_manager_plusMatch4.1build4101
OR
zohocorpmanageengine_access_manager_plusMatch4.2build4200
OR
zohocorpmanageengine_access_manager_plusMatch4.2build4201
OR
zohocorpmanageengine_access_manager_plusMatch4.2build4202
OR
zohocorpmanageengine_access_manager_plusMatch4.2build4203
OR
zohocorpmanageengine_access_manager_plusMatch4.3build4300
OR
zohocorpmanageengine_access_manager_plusMatch4.3build4301
OR
zohocorpmanageengine_pam360Match4.0build4001
OR
zohocorpmanageengine_pam360Match4.0build4002
OR
zohocorpmanageengine_pam360Match4.1build4100
OR
zohocorpmanageengine_pam360Match4.1build4101
OR
zohocorpmanageengine_pam360Match4.5build4500
OR
zohocorpmanageengine_pam360Match4.5build4501
OR
zohocorpmanageengine_pam360Match5.0build5000
OR
zohocorpmanageengine_pam360Match5.0build5001
OR
zohocorpmanageengine_pam360Match5.0build5002
OR
zohocorpmanageengine_pam360Match5.0build5003
OR
zohocorpmanageengine_pam360Match5.0build5004
OR
zohocorpmanageengine_pam360Match5.1build5100
OR
zohocorpmanageengine_pam360Match5.2build5200
OR
zohocorpmanageengine_pam360Match5.3build5300
OR
zohocorpmanageengine_pam360Match5.3build5301
OR
zohocorpmanageengine_pam360Match5.3build5302
OR
zohocorpmanageengine_pam360Match5.4build5400
OR
zohocorpmanageengine_password_manager_proMatch10.1build10103
OR
zohocorpmanageengine_password_manager_proMatch10.1build10104
OR
zohocorpmanageengine_password_manager_proMatch10.2build10200
OR
zohocorpmanageengine_password_manager_proMatch10.3build10300
OR
zohocorpmanageengine_password_manager_proMatch10.3build10301
OR
zohocorpmanageengine_password_manager_proMatch10.3build10302
OR
zohocorpmanageengine_password_manager_proMatch10.4build10400
OR
zohocorpmanageengine_password_manager_proMatch10.4build10401
OR
zohocorpmanageengine_password_manager_proMatch10.4build10402
OR
zohocorpmanageengine_password_manager_proMatch11.111104
OR
zohocorpmanageengine_password_manager_proMatch11.1build_11101
OR
zohocorpmanageengine_password_manager_proMatch11.1build_11102
OR
zohocorpmanageengine_password_manager_proMatch11.1build_11103
OR
zohocorpmanageengine_password_manager_proMatch11.211200
OR
zohocorpmanageengine_password_manager_proMatch11.211201
OR
zohocorpmanageengine_password_manager_proMatch11.3build11300
OR
zohocorpmanageengine_password_manager_proMatch11.3build11301
OR
zohocorpmanageengine_password_manager_proMatch12.0build12000
OR
zohocorpmanageengine_password_manager_proMatch12.0build12001
OR
zohocorpmanageengine_password_manager_proMatch12.0build12002
OR
zohocorpmanageengine_password_manager_proMatch12.0build12003
OR
zohocorpmanageengine_password_manager_proMatch12.0build12004
OR
zohocorpmanageengine_password_manager_proMatch12.0build12005
OR
zohocorpmanageengine_password_manager_proMatch12.0build12006

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.517 Medium

EPSS

Percentile

97.6%