Vulnerability record · CVE-2022-29081 · published 28 April 2022
CVE-2022-29081: Zoho ManageEngine PAM products access-control bypass via path traversal
Zohocorp · Manageengine Access Manager Plus
Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, Synchronize) when the request path contains the ../RestAPI substring. Because these are privileged PAM components, bypassing authentication exposes credential vault and session-management functionality. The flaw is rated CVSS 9.8 critical and has a very high EPSS score, so it warrants urgent attention.
Description
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, high EPSS, and public exploit detail against internet-facing privileged-access-management systems.
What it is
Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents, Synchronize) when the request path contains the ../RestAPI substring. Because these are privileged PAM components, bypassing authentication exposes credential vault and session-management functionality. The flaw is rated CVSS 9.8 critical and has a very high EPSS score, so it warrants urgent attention.
Impact
An unauthenticated remote attacker can reach REST API functionality that should require authentication, potentially reading or manipulating privileged-access-management data such as managed credentials and session records. The full scope of what each endpoint exposes is not detailed in the record.
Attack surface
Reachable over the network through the affected REST API URLs; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. The bypass is triggered by including the ../RestAPI substring in the request path.
Exploitation
Not listed in CISA KEV, but EPSS is 0.835 (99.7th percentile) and a Tenable research reference is tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.
What to do
- Upgrade Access Manager Plus to 4302 or later, Password Manager Pro to 12007 or later, and PAM360 to 5401 or later.
- If immediate patching is not possible, restrict network access to the PAM web/REST interfaces to trusted management networks only.
- Block or normalize request paths containing ../RestAPI at the reverse proxy or WAF and reject traversal sequences.
- Audit PAM logs for unexpected REST API calls to the listed endpoints and rotate any credentials that may have been exposed.
Detection
- Search web/proxy logs for requests whose URI contains ../RestAPI, especially to SSOutAction, SSLAction, LicenseMgr, GetProductDetails, GetDashboard, FetchEvents or Synchronize.
- Alert on unauthenticated or anomalous access to those REST endpoints from unfamiliar source IPs.
- Monitor PAM application logs for access-control or path-normalization errors tied to these endpoints.
- Correlate any successful hits with subsequent credential retrieval or configuration changes in the PAM audit trail.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/privileged-session-management/advisory/cve-2022-29081.html | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2022-14 | ExploitThird Party Advisory |
| https://www.manageengine.com/privileged-session-management/advisory/cve-2022-29081.html | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2022-14 | ExploitThird Party Advisory |
Track CVE-2022-29081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.