Vulnerability record · CVE-2022-43671 · published 12 November 2022
CVE-2022-43671: Zoho ManageEngine Password Manager Pro, PAM360, Access Manager Plus SQL injection
Zohocorp · Manageengine Access Manager Plus
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 are vulnerable to SQL injection. The flaw is remotely reachable with no authentication or user interaction, and the affected products are privileged-access and password-management systems, so a compromise can expose the credentials they are meant to protect.
Description
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and high EPSS on credential-management products makes this a top remediation priority.
What it is
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 are vulnerable to SQL injection. The flaw is remotely reachable with no authentication or user interaction, and the affected products are privileged-access and password-management systems, so a compromise can expose the credentials they are meant to protect.
Impact
An unauthenticated attacker can inject SQL to read or alter database contents, potentially extracting stored secrets and administrative data. Because the products manage privileged credentials, this can lead to broader compromise of managed systems.
Attack surface
Reachable over the network via the affected web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.7483 (99.5th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Password Manager Pro to 12122 or later, PAM360 to 5711 or later, and Access Manager Plus to 4306 or later.
- If immediate patching is not possible, restrict network access to the affected web interfaces to trusted management networks only.
- Place the products behind a WAF or reverse proxy with SQL injection filtering as a temporary control.
- Rotate credentials and secrets stored in the affected products if compromise is suspected.
- Monitor vendor advisory for any updated guidance.
Detection
- Review web server and application logs for SQL metacharacters or injection patterns in requests to the affected interfaces.
- Alert on unexpected database queries or errors originating from the web application.
- Audit for anomalous access to credential stores or administrative functions.
- Correlate outbound connections from the affected hosts with known scanning or exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-43671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-43671), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.