Zohocorp
Zohocorp Manageengine Access Manager Plus: vulnerabilities and CVEs
Zohocorp Manageengine Access Manager Plus has 11 published vulnerabilities, 1 of them in the last 12 months. 8 are rated critical and 2 are listed by CISA as actively exploited.
CVEs11
Last 12 months1
Critical8
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-47966 | Critical (9.8) | 100% | ⚠ Active exploitation | Jan 18, 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
| CVE-2022-35405 | Critical (9.8) | 100% | ⚠ Active exploitation | Jul 19, 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11669 | High (8.1) | 0.80% | — | Jan 13, 2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session… |
| CVE-2023-6105 | Medium (5.5) | 0.69% | — | Nov 15, 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product… |
| CVE-2023-2291 | High (7.8) | 0.81% | — | Apr 26, 2023 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to… |
| CVE-2022-47966 | Critical (9.8) | 100% | ⚠ Active exploitation | Jan 18, 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
| CVE-2022-47523 | Critical (9.8) | 71% | — | Jan 5, 2023 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. |
| CVE-2022-43672 | Critical (9.8) | 67% | — | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. |
| CVE-2022-43671 | Critical (9.8) | 75% | — | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. |
| CVE-2022-40300 | Critical (9.8) | 99% | — | Sep 16, 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. |
| CVE-2022-35405 | Critical (9.8) | 100% | ⚠ Active exploitation | Jul 19, 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
| CVE-2022-29081 | Critical (9.8) | 84% | — | Apr 28, 2022 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr.… |
| CVE-2021-44676 | Critical (9.8) | 4.4% | — | Dec 20, 2021 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Adaudit Plus · 53Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Exchange Reporter Plus · 28Manageengine Assetexplorer · 26Manageengine Servicedesk Plus MSP · 26