Zohocorp
Zohocorp Manageengine Password Manager PRO: vulnerabilidades y CVE
Zohocorp Manageengine Password Manager PRO tiene 25 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 8 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses4
Críticas8
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-47966 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 ene 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
| CVE-2022-35405 | Crítica (9.8) | 100% | ⚠ Explotación activa | 19 jul 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12263 | Alta (8.8) | 1.4% | — | 13 ago 2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. |
| CVE-2026-11840 | Alta (8.8) | 3.1% | — | 13 ago 2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. |
| CVE-2026-5785 | Alta (8.1) | 2.6% | — | 16 abr 2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. |
| CVE-2025-11669 | Alta (8.1) | 0.80% | — | 13 ene 2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session… |
| CVE-2024-5546 | Alta (8.8) | 3.0% | — | 28 ago 2024 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option. |
| CVE-2023-6105 | Media (5.5) | 0.69% | — | 15 nov 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product… |
| CVE-2020-27449 | Media (6.1) | 3.1% | — | 11 ago 2023 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript… |
| CVE-2023-2291 | Alta (7.8) | 0.81% | — | 26 abr 2023 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to… |
| CVE-2022-47966 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 ene 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
| CVE-2022-47523 | Crítica (9.8) | 71% | — | 5 ene 2023 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. |
| CVE-2022-43672 | Crítica (9.8) | 67% | — | 12 nov 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. |
| CVE-2022-43671 | Crítica (9.8) | 75% | — | 12 nov 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. |
| CVE-2022-40300 | Crítica (9.8) | 99% | — | 16 sept 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. |
| CVE-2022-35405 | Crítica (9.8) | 100% | ⚠ Explotación activa | 19 jul 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
| CVE-2022-29081 | Crítica (9.8) | 84% | — | 28 abr 2022 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr.… |
| CVE-2021-33617 | Media (5.3) | 2.1% | — | 31 jul 2021 | Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the… |
| CVE-2021-31857 | Media (5.9) | 3.1% | — | 16 jun 2021 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types. |
| CVE-2020-9347 | Crítica (9.8) | 7.8% | — | 16 mar 2020 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this… |
| CVE-2020-9346 | Alta (8.8) | 2.2% | — | 16 mar 2020 | Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. |
| CVE-2016-1159 | Media (6.5) | 4.4% | — | 9 mar 2020 | In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service. |
| CVE-2019-12133 | Alta (7.8) | 1.7% | — | 18 jun 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said… |
| CVE-2017-17698 | Media (6.1) | 1.5% | — | 15 dic 2017 | Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. |
| CVE-2015-5459 | Media (6.5) | 3.5% | — | 8 jul 2015 | SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via… |
| CVE-2014-3997 | Alta (7.5) | 13% | — | 5 dic 2014 | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed… |
| CVE-2014-8498 | Media (6.5) | 13% | — | 17 nov 2014 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Adaudit Plus · 53Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Exchange Reporter Plus · 28Manageengine Servicedesk Plus MSP · 26Manageengine Assetexplorer · 26