CVE-2022-29081 is a critical access-control bypass vulnerability affecting Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401. This flaw allows unauthenticated attackers to bypass security controls on specific Rest API URLs by injecting the "../RestAPI" substring. With a CVSS score of 9.8 (CRITICAL), successful exploitation could lead to complete compromise of confidentiality, integrity, and availability of the affected systems. While not currently listed in CISA's KEV catalog or showing active exploitation, public Nuclei templates exist, indicating readily available exploit code and a high potential for future attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.0:build4000:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.1:build4100:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.1:build4101:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.2:build4200:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.2:build4201:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ManageEngine Access Manager Plus REST API Restriction Bypass
Apr 27, 2022ManageEngine Access Manager Plus REST API Restriction Bypass
Apr 27, 2022ManageEngine Access Manager Plus REST API Restriction Bypass
Apr 27, 2022