Vulnerability record · CVE-2022-40300 · published 16 September 2022
CVE-2022-40300: Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injection
Zohocorp · Manageengine Access Manager Plus
Zoho ManageEngine Password Manager Pro (through 12120), PAM360 (through 5550) and Access Manager Plus (through 4304) contain multiple SQL injection vulnerabilities fixed in later builds. Because these are privileged credential and PAM products, a successful injection can expose or alter the sensitive data they are meant to protect.
Description
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and very high EPSS make this a top remediation priority despite no KEV listing.
What it is
Zoho ManageEngine Password Manager Pro (through 12120), PAM360 (through 5550) and Access Manager Plus (through 4304) contain multiple SQL injection vulnerabilities fixed in later builds. Because these are privileged credential and PAM products, a successful injection can expose or alter the sensitive data they are meant to protect.
Impact
An unauthenticated attacker can read and modify database contents, potentially including stored credentials and administrative data, and may achieve full compromise of the application's data layer.
Attack surface
Reachable over the network via the affected web interfaces with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific vulnerable endpoints or parameters.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is very high (0.99123, 99.9th percentile), indicating elevated predicted exploitation likelihood, and the only references are the vendor patch advisories.
What to do
- Upgrade Password Manager Pro to 12121 or later, PAM360 to 5600 or later, and Access Manager Plus to 4305 or later per the vendor advisory.
- If immediate patching is not possible, restrict network access to these web interfaces to trusted management networks only.
- Review database and application logs for anomalous SQL activity and unexpected queries against the product databases.
- Rotate credentials and secrets stored in the affected products if compromise is suspected.
- Monitor vendor advisories for any further updates on these vulnerabilities.
Detection
- Inspect web server and WAF logs for SQL metacharacters and injection patterns in requests to the Password Manager Pro, PAM360 and Access Manager Plus interfaces.
- Alert on unexpected database queries or errors originating from the application service accounts.
- Baseline and monitor outbound or unusual database access from the application hosts for signs of data exfiltration.
- Audit application accounts and configuration changes for unauthorized modifications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.html | PatchVendor Advisory |
| https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-40300.html | PatchVendor Advisory |
Track CVE-2022-40300 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-40300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.