ZeroHour
Security Affairspublished ()ingested @securityaffairs

Zoho urges fixing a critical SQL Injection flaw in ManageEngine

criticalVulnerability exploited in the wildimportance 60CVE-2022-47523CVE-2022-35405

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-35405
Deserialization RCE in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain a flaw classified as deserialization of untrusted data (CWE-502) that allows an unauthenticated attacker to achieve remote code execution by sending crafted serialized data to the server. Because no authentication or user interaction is required, any client that can reach the product's network service can submit input that the application deserializes and executes. A successful attacker gains code execution with the privileges of the product's service, typically yielding control of the server and, critically, access to the vault of privileged credentials these products store, enabling lateral movement and ransomware campaigns. Any organization running one of these three ManageEngine password and access management products is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-22, and EPSS estimates a 99.9% probability of exploitation within 30 days.

Do: Apply the updates Zoho released for all three products immediately, as CISA's required action specifies applying vendor updates: inventory whether you run Password Manager Pro, PAM360, or Access Manager Plus, and upgrade to the fixed builds named in each product's advisory. Until patched, restrict network access to the products' HTTPS management service (e.g., Password Manager Pro's default service port 7272) to trusted administrative networks only. After patching, hunt for signs of compromise such as unexpected processes, new accounts, or use of vaulted credentials, since the KEV listing implies exploitation and ransomware association is listed as unknown.

9.8100% KEV PoC
  • Zoho ManageEngine Password Manager Pro
  • Zoho ManageEngine PAM360
  • Zoho ManageEngine Access Manager Plus
largetens of thousands of enterprise deployments across the three products, including several thousand internet-exposed instances visible in public scans,…
CVE-2022-47523
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

NVD description · AI analysis pending
9.871%
  • zohocorp manageengine password manager pro
  • zohocorp manageengine pam360
  • zohocorp manageengine access manager plus
Full article260 words · extracted from securityaffairs.com · click to collapse

Zoho is warning its customers of a critical vulnerability, tracked as CVE-2022-47523, affecting multiple ManageEngine products.

Zoho is urging its customers to address a critical SQL Injection vulnerability, tracked as CVE-2022-47523, that affects multiple ManageEngine products.

“This security advisory is to let you know that a high severity vulnerability was detected in ManageEngine Password Manager Pro.” reads the advisory published by Zoho. “An SQL Injection vulnerability(CVE-2022-47523) was discovered in Password Manager Pro.”

An attacker can trigger this vulnerability to execute custom queries, and access the database records using the vulnerable request.

The vendor addressed the flaw by adding proper validation and escaping special characters.

The flaw impacts Password Manager Pro, versions 12200 and below.

“We identified a SQL injection vulnerability (CVE-2022-47523) in our internal framework that would grant access to all the Password Manager Pro users to the backend database. It has now been fixed.” Zoho added.

Below are the steps to upgrade the installs:

  • Download the latest upgrade pack from here.
  • Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

In September, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw in Zoho ManageEngine, tracked as CVE-2022-35405 (CVSS score 9.8), to its Known Exploited Vulnerabilities Catalog.

The CVE-2022-35405 flaw is a remote code execution vulnerability that impacts ManageEngine PAM360, Password Manager Pro, and Access Manager Plus.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, SQL Injection)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/140369/security/zoho-sql-injection-manageengine.html