CVE-2022-47523: Zohocorp ManageEngine Access Manager Plus
Critical severity, CVSS 9.8. EPSS: 70.6% chance of exploitation in the next 30 days.
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
Affected products
- Zohocorp ManageEngine Access Manager Plus: before 4.3 (fixed in 4.3); version 4.3 only
- Zohocorp ManageEngine PAM360: before 5.8 (fixed in 5.8); version 5.8 only
- Zohocorp ManageEngine Password Manager Pro: before 12.2 (fixed in 12.2); version 12.2 only
Published 2023-01-05. Last modified 2026-06-17.