Vulnerability Database

383,463

Total vulnerabilities in the database

CVE-2022-29081 — zohocorp / manageengine_access_manager_plus

Incorrect Authorization

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

  • Published: Apr 28, 2022
  • Updated: Sep 13, 2026
  • CVE: CVE-2022-29081
  • Severity: Critical
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software Affected versions
zohocorp / manageengine_access_manager_plus = 4.0-build4000
zohocorp / manageengine_access_manager_plus = 4.1-build4100
zohocorp / manageengine_access_manager_plus = 4.1-build4101
zohocorp / manageengine_access_manager_plus = 4.2-build4200
zohocorp / manageengine_access_manager_plus = 4.2-build4201
zohocorp / manageengine_access_manager_plus = 4.2-build4202
zohocorp / manageengine_access_manager_plus = 4.2-build4203
zohocorp / manageengine_access_manager_plus = 4.3-build4300
zohocorp / manageengine_access_manager_plus = 4.3-build4301
zohocorp / manageengine_pam360 = 4.0-build4001
zohocorp / manageengine_pam360 = 4.0-build4002
zohocorp / manageengine_pam360 = 4.1-build4100
zohocorp / manageengine_pam360 = 4.1-build4101
zohocorp / manageengine_pam360 = 4.5-build4500
zohocorp / manageengine_pam360 = 4.5-build4501
zohocorp / manageengine_pam360 = 5.0-build5000
zohocorp / manageengine_pam360 = 5.0-build5001
zohocorp / manageengine_pam360 = 5.0-build5002
zohocorp / manageengine_pam360 = 5.0-build5003
zohocorp / manageengine_pam360 = 5.0-build5004
zohocorp / manageengine_pam360 = 5.1-build5100
zohocorp / manageengine_pam360 = 5.2-build5200
zohocorp / manageengine_pam360 = 5.3-build5300
zohocorp / manageengine_pam360 = 5.3-build5301
zohocorp / manageengine_pam360 = 5.3-build5302
zohocorp / manageengine_pam360 = 5.4-build5400
zohocorp / manageengine_password_manager_pro = 10.1-build10103
zohocorp / manageengine_password_manager_pro = 10.1-build10104
zohocorp / manageengine_password_manager_pro = 10.2-build10200
zohocorp / manageengine_password_manager_pro = 10.3-build10300
zohocorp / manageengine_password_manager_pro = 10.3-build10301
zohocorp / manageengine_password_manager_pro = 10.3-build10302
zohocorp / manageengine_password_manager_pro = 10.4-build10400
zohocorp / manageengine_password_manager_pro = 10.4-build10401
zohocorp / manageengine_password_manager_pro = 10.4-build10402
zohocorp / manageengine_password_manager_pro = 11.1-11104
zohocorp / manageengine_password_manager_pro = 11.1-build_11101
zohocorp / manageengine_password_manager_pro = 11.1-build_11102
zohocorp / manageengine_password_manager_pro = 11.1-build_11103
zohocorp / manageengine_password_manager_pro = 11.2-build11200
zohocorp / manageengine_password_manager_pro = 11.2-build11201
zohocorp / manageengine_password_manager_pro = 11.3-build11300
zohocorp / manageengine_password_manager_pro = 11.3-build11301
zohocorp / manageengine_password_manager_pro = 12.0-build12000
zohocorp / manageengine_password_manager_pro = 12.0-build12001
zohocorp / manageengine_password_manager_pro = 12.0-build12002
zohocorp / manageengine_password_manager_pro = 12.0-build12003
zohocorp / manageengine_password_manager_pro = 12.0-build12004
zohocorp / manageengine_password_manager_pro = 12.0-build12005
zohocorp / manageengine_password_manager_pro = 12.0-build12006

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.