CVE-2022-47523: Zohocorp ManageEngine Access Manager Plus

Critical severity, CVSS 9.8. EPSS: 70.6% chance of exploitation in the next 30 days.

Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

Affected products

  • Zohocorp ManageEngine Access Manager Plus: before 4.3 (fixed in 4.3); version 4.3 only
  • Zohocorp ManageEngine PAM360: before 5.8 (fixed in 5.8); version 5.8 only
  • Zohocorp ManageEngine Password Manager Pro: before 12.2 (fixed in 12.2); version 12.2 only

Published 2023-01-05. Last modified 2026-06-17.