← Vulnerability feed

Vulnerability record · CVE-2022-35405 · published 19 July 2022

CVE-2022-35405: Zoho ManageEngine Password Manager Pro unauthenticated deserialization RCE

Zohocorp · Manageengine Access Manager Plus

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserialization of untrusted data. Access Manager Plus before 4303 is also affected, but requires authentication. The flaw is critical because it allows code execution without credentials on internet-reachable instances of a privileged credential-management product.

9.8 CVSS 3.1 Critical CISA KEV since 22 Sep 2022 EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution in a credential-management product, with a CVSS score of 9.8, KEV listing and near-maximum EPSS probability.

What it is

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserialization of untrusted data. Access Manager Plus before 4303 is also affected, but requires authentication. The flaw is critical because it allows code execution without credentials on internet-reachable instances of a privileged credential-management product.

Impact

An unauthenticated attacker can execute arbitrary code on the affected server, gaining control of a system that stores and brokers privileged credentials. This can lead to theft of managed secrets and lateral movement into connected infrastructure.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), and the public exploit reference describes an XML-RPC Java deserialization path. For Password Manager Pro and PAM360 no authentication is needed; Access Manager Plus requires authentication.

Exploitation

CVE-2022-35405 is listed in CISA KEV with a due date of 2022-10-13, and EPSS shows a 30-day probability of 0.99927 (99.97th percentile). Public exploit code is referenced, and CISA records no known ransomware campaign use.

What to do

  • Apply the vendor updates: Password Manager Pro 12101 or later, PAM360 5510 or later, Access Manager Plus 4303 or later.
  • If patching cannot be done immediately, remove direct internet exposure of these products and restrict access to trusted management networks.
  • Block or restrict access to the XML-RPC endpoint at the network or reverse-proxy layer until the patch is applied.
  • Rotate credentials and secrets stored in the affected product after patching, assuming possible prior compromise.
  • Monitor vendor advisories for any follow-up guidance on the affected builds.

Detection

  • Hunt for POST requests to XML-RPC endpoints on Password Manager Pro, PAM360 and Access Manager Plus hosts, especially from unexpected source addresses.
  • Look for unexpected child processes spawned by the Java service hosting these products, such as shells or scripting interpreters.
  • Review application and web server logs for deserialization errors or anomalous XML-RPC payloads preceding process creation.
  • Check for outbound connections from the product server to unfamiliar hosts that could indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-35405 to the Known Exploited Vulnerabilities catalog on 22 September 2022 as "Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 October 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-35405 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2022-47523Zoho ManageEngine PAM products SQL injectionZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respective…EPSS 71%analysed9.8CVE-2022-43671Zoho ManageEngine Password Manager Pro, PAM360, Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 are vulnerable to SQL injection. The fla…EPSS 75%analysed9.8CVE-2022-43672Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 contain a SQL injection flaw in a softwa…EPSS 67%analysed9.8CVE-2022-40300Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro (through 12120), PAM360 (through 5550) and Access Manager Plus (through 4304) contain multiple SQL injection v…EPSS 99%analysed9.8CVE-2022-29081Zoho ManageEngine PAM products access-control bypass via path traversalZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSL…EPSS 84%analysed9.8CVE-2021-44525Zohocorp manageengine pam360 improper authentication vulnerabilityZoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…EPSS 3.4%9.8CVE-2021-44676Zohocorp manageengine access manager plus improper authentication vulnerabilityZoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2022-35405), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.