VendorsZoho Corpmanageengine_password_manager_pro11.2
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine Password Manager Pro 11.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-40300
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Published 2022-09-16 · Analyzed
9.8EPSS 0.991
CVE-2022-29081
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Published 2022-04-28 · Analyzed
9.8EPSS 0.835
CVE-2024-5546
SQL Injection
Published 2024-08-28 · Analyzed
8.8EPSS 0.030
CVE-2021-33617
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
Published 2021-07-31 · Modified
5.3EPSS 0.021