CVE-2022-35404: Zohocorp ManageEngine Firewall Analyzer

High severity, CVSS 8.2. EPSS: 2.9% chance of exploitation in the next 30 days.

ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.

Affected products

  • Zohocorp ManageEngine Firewall Analyzer: before 12.5 (fixed in 12.5); version 12.5 only
  • Zohocorp ManageEngine Netflow Analyzer: before 12.5 (fixed in 12.5); version 12.5 only
  • Zohocorp ManageEngine Network Configuration Manager: before 12.5 (fixed in 12.5); version 12.5 only
  • Zohocorp ManageEngine Opmanager: before 12.5 (fixed in 12.5); version 12.5 only

Published 2022-07-18. Last modified 2026-06-17.