Vulnerability record · CVE-2022-43672 · published 12 November 2022
CVE-2022-43672: Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injection
Zohocorp · Manageengine Access Manager Plus
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 contain a SQL injection flaw in a software component distinct from CVE-2022-43671. Because these are privileged credential and privileged access management products, a successful injection can expose or corrupt the sensitive data they are meant to protect.
Description
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and no user interaction, combined with a very high EPSS score, makes this an urgent patch target despite the absence of KEV listing.
What it is
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 contain a SQL injection flaw in a software component distinct from CVE-2022-43671. Because these are privileged credential and privileged access management products, a successful injection can expose or corrupt the sensitive data they are meant to protect.
Impact
An attacker can execute arbitrary SQL against the underlying database, potentially reading, modifying, or deleting stored data, including credentials and configuration held by these PAM products. The CVSS vector rates confidentiality, integrity, and availability impact as high.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning the flaw is reachable over the network with no authentication and no user interaction. The description does not identify the specific endpoint or parameter, so the exact injection point is not stated in the record.
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is 0.67078 (99.265th percentile), indicating a high predicted likelihood of exploitation activity. The only references are vendor advisories, so no public exploit code or in-the-wild confirmation is documented here.
What to do
- Upgrade Password Manager Pro to 12122 or later, PAM360 to 5711 or later, and Access Manager Plus to 4306 or later.
- If immediate patching is not possible, restrict network access to these products to trusted management networks and remove any internet exposure.
- Review database and application logs for anomalous SQL or unexpected query errors around the affected component.
- Rotate credentials and secrets stored in the affected products if compromise is suspected.
- Apply input validation and parameterized query fixes per the vendor advisory for the affected component.
Detection
- Monitor web and application logs for SQL metacharacters or injection patterns in requests to the affected product.
- Alert on unexpected database errors or unusual query volume originating from the application servers.
- Audit database accounts and permissions used by these products for signs of unauthorized access or schema changes.
- Correlate authentication and access logs for anomalous activity from unauthenticated or unexpected source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-43672 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-43672), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.