Critical severity9.8NVD Advisory· Published Nov 12, 2022· Updated Jun 17, 2026
CVE-2022-43672
CVE-2022-43672
Description
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:*range: <4.3
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4300:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4301:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4302:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4303:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4304:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4305:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*range: <5.7
- cpe:2.3:a:zohocorp:manageengine_pam360:5.7:build5700:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_pam360:5.7:build5710:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*range: <12.1
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.1:build12100:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.1:build12101:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.1:build12110:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.1:build12120:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.1:build12121:*:*:*:*:*:*
- Range: <4306
- Range: <12122
- Range: <5711
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.