Vulnerability record · CVE-2022-35405 · published 19 July 2022
CVE-2022-35405: Zoho ManageEngine Password Manager Pro unauthenticated deserialization RCE
Zohocorp · Manageengine Access Manager Plus
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserialization of untrusted data. Access Manager Plus before 4303 is also affected, but requires authentication. The flaw is critical because it allows code execution without credentials on internet-reachable instances of a privileged credential-management product.
Description
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution in a credential-management product, with a CVSS score of 9.8, KEV listing and near-maximum EPSS probability.
What it is
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserialization of untrusted data. Access Manager Plus before 4303 is also affected, but requires authentication. The flaw is critical because it allows code execution without credentials on internet-reachable instances of a privileged credential-management product.
Impact
An unauthenticated attacker can execute arbitrary code on the affected server, gaining control of a system that stores and brokers privileged credentials. This can lead to theft of managed secrets and lateral movement into connected infrastructure.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), and the public exploit reference describes an XML-RPC Java deserialization path. For Password Manager Pro and PAM360 no authentication is needed; Access Manager Plus requires authentication.
Exploitation
CVE-2022-35405 is listed in CISA KEV with a due date of 2022-10-13, and EPSS shows a 30-day probability of 0.99927 (99.97th percentile). Public exploit code is referenced, and CISA records no known ransomware campaign use.
What to do
- Apply the vendor updates: Password Manager Pro 12101 or later, PAM360 5510 or later, Access Manager Plus 4303 or later.
- If patching cannot be done immediately, remove direct internet exposure of these products and restrict access to trusted management networks.
- Block or restrict access to the XML-RPC endpoint at the network or reverse-proxy layer until the patch is applied.
- Rotate credentials and secrets stored in the affected product after patching, assuming possible prior compromise.
- Monitor vendor advisories for any follow-up guidance on the affected builds.
Detection
- Hunt for POST requests to XML-RPC endpoints on Password Manager Pro, PAM360 and Access Manager Plus hosts, especially from unexpected source addresses.
- Look for unexpected child processes spawned by the Java service hosting these products, such as shells or scripting interpreters.
- Review application and web server logs for deserialization errors or anomalous XML-RPC payloads preceding process creation.
- Check for outbound connections from the product server to unfamiliar hosts that could indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-35405 to the Known Exploited Vulnerabilities catalog on 22 September 2022 as "Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 October 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html | PatchVendor Advisory |
| http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35405 | US Government Resource |
Track CVE-2022-35405 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-35405), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.