Vulnerability record · CVE-2022-47523 · published 5 January 2023
CVE-2022-47523: Zoho ManageEngine PAM products SQL injection
Zohocorp · Manageengine Password Manager Pro
Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respectively. Because these are privileged access management products, a successful injection can expose or alter the credential vault data they are meant to protect.
Description
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this an urgent patch for internet-exposed PAM deployments.
What it is
Zoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respectively. Because these are privileged access management products, a successful injection can expose or alter the credential vault data they are meant to protect.
Impact
An unauthenticated attacker can read, modify or destroy data in the underlying database, potentially including stored privileged credentials and session records. Full loss of confidentiality, integrity and availability of the application is possible.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The specific vulnerable endpoint or parameter is not described in the record.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.706 (99.4th percentile), indicating elevated likelihood of attempted exploitation. The only references are the vendor patch advisories, so no public exploit code is confirmed by this record.
What to do
- Upgrade Access Manager Plus to 4309 or later, Password Manager Pro to 12210 or later, and PAM360 to 5801 or later.
- If immediate patching is not possible, restrict network access to these PAM web interfaces to trusted management networks only.
- Review database and application logs for anomalous SQL activity against the PAM instances.
- Rotate privileged credentials stored in the affected products as a precaution if compromise is suspected.
- Confirm no unauthorized administrative accounts or configuration changes were created in the PAM platform.
Detection
- Search web and database logs for SQL metacharacters or UNION/boolean patterns in requests to the PAM application.
- Alert on unexpected database queries or errors originating from the PAM application service account.
- Monitor for new or modified accounts, roles or vault entries in Access Manager Plus, Password Manager Pro and PAM360.
- Correlate outbound connections from PAM hosts to unfamiliar destinations that could indicate data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html | PatchVendor Advisory |
| https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html | PatchVendor Advisory |
Track CVE-2022-47523 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-47523), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.