peter bassill · operator
$ cve CVE-2022-40300 JSON

CVE-2022-40300

9.8
CRITICAL · CVSS 3.1 · EPSS 99.1% (pctl 100)

Patch early

EPSS 99.1% — above the 10% action threshold.

Description

Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.12% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2022-09-16
Last modified2026-06-17

Affected (3)

VendorProduct
zohocorpmanageengine access manager plus
zohocorpmanageengine pam360
zohocorpmanageengine password manager pro

References

→ the Explorer  ·  watch your stack  ·  NVD