CVE-2022-40300
9.8
CRITICAL · CVSS 3.1 · EPSS 99.1% (pctl 100)
Patch early
EPSS 99.1% — above the 10% action threshold.
Description
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.12% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-09-16 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| zohocorp | manageengine access manager plus |
| zohocorp | manageengine pam360 |
| zohocorp | manageengine password manager pro |
References
→ the Explorer · watch your stack · NVD