← Vulnerability feed

Vulnerability record · CVE-2022-29081 · published 28 April 2022

CVE-2022-29081: Zoho ManageEngine PAM products access-control bypass via path traversal

Zohocorp · Manageengine Access Manager Plus

Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, Synchronize) when the request path contains the ../RestAPI substring. Because these are privileged PAM components, bypassing authentication exposes credential vault and session-management functionality. The flaw is rated CVSS 9.8 critical and has a very high EPSS score, so it warrants urgent attention.

9.8 CVSS 3.1 Critical EPSS 84% · top 0.3% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, high EPSS, and public exploit detail against internet-facing privileged-access-management systems.

What it is

Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, Synchronize) when the request path contains the ../RestAPI substring. Because these are privileged PAM components, bypassing authentication exposes credential vault and session-management functionality. The flaw is rated CVSS 9.8 critical and has a very high EPSS score, so it warrants urgent attention.

Impact

An unauthenticated remote attacker can reach REST API functionality that should require authentication, potentially reading or manipulating privileged-access-management data such as managed credentials and session records. The full scope of what each endpoint exposes is not detailed in the record.

Attack surface

Reachable over the network through the affected REST API URLs; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. The bypass is triggered by including the ../RestAPI substring in the request path.

Exploitation

Not listed in CISA KEV, but EPSS is 0.835 (99.7th percentile) and a Tenable research reference is tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.

What to do

  • Upgrade Access Manager Plus to 4302 or later, Password Manager Pro to 12007 or later, and PAM360 to 5401 or later.
  • If immediate patching is not possible, restrict network access to the PAM web/REST interfaces to trusted management networks only.
  • Block or normalize request paths containing ../RestAPI at the reverse proxy or WAF and reject traversal sequences.
  • Audit PAM logs for unexpected REST API calls to the listed endpoints and rotate any credentials that may have been exposed.

Detection

  • Search web/proxy logs for requests whose URI contains ../RestAPI, especially to SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents or Synchronize.
  • Alert on unauthenticated or anomalous access to those REST endpoints from unfamiliar source IPs.
  • Monitor PAM application logs for access-control or path-normalization errors tied to these endpoints.
  • Correlate any successful hits with subsequent credential retrieval or configuration changes in the PAM audit trail.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2022-35405Zoho ManageEngine Password Manager Pro unauthenticated deserialization RCEZoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserializatio…KEVEPSS 100%analysed9.8CVE-2022-47523Zoho ManageEngine PAM products SQL injectionZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respective…EPSS 71%analysed9.8CVE-2022-43671Zoho ManageEngine Password Manager Pro, PAM360, Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 are vulnerable to SQL injection. The fla…EPSS 75%analysed9.8CVE-2022-43672Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 contain a SQL injection flaw in a softwa…EPSS 67%analysed9.8CVE-2022-40300Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro (through 12120), PAM360 (through 5550) and Access Manager Plus (through 4304) contain multiple SQL injection v…EPSS 99%analysed9.8CVE-2021-44525Zohocorp manageengine pam360 improper authentication vulnerabilityZoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…EPSS 3.4%9.8CVE-2021-44676Zohocorp manageengine access manager plus improper authentication vulnerabilityZoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2022-29081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.