CVE-2022-35405

zohocorp manageengine access manager plus, zohocorp manageengine pam360, zohocorp manageengine password manager pro

Published 19 Jul 2022 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 22 Sept 2022, with a remediation deadline of 13 Oct 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

References