CVE-2023-2291: Zohocorp ManageEngine Access Manager Plus

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.

Affected products

  • Zohocorp ManageEngine Access Manager Plus: version 4.3 only
  • Zohocorp ManageEngine PAM360: any version
  • Zohocorp ManageEngine Password Manager Pro: any version

Published 2023-04-26. Last modified 2026-06-17.