2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-47523" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-01-05T08:15:08.877" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:32:08.650" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Zoho ManageEngine Access Manager Plus anterior a 4309, Password Manager Pro anterior a 12210 y PAM360 anterior a 5801 son vulnerables a la inyecci\u00f3n SQL."
2023-04-24 12:24:31 +02:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-89"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "12.2" ,
"matchCriteriaId" : "8B2A2278-0B89-44FB-9D95-30647BBA63D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:12.2:build12200:*:*:*:*:*:*" ,
"matchCriteriaId" : "45976216-66CF-45D6-9940-280594D711D1"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.8" ,
"matchCriteriaId" : "19340150-5197-4F06-96EF-FE4A29AE2B9B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_pam360:5.8:build5800:*:*:*:*:*:*" ,
"matchCriteriaId" : "17933D57-20D9-47A0-B29C-5B06D0B90F92"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.3" ,
"matchCriteriaId" : "5FDF15FF-2561-4139-AC5E-4812584B1B03"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4300:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5DEC045-6A7E-4041-88F8-5ABC4AB51C29"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4301:*:*:*:*:*:*" ,
"matchCriteriaId" : "52DDE5D9-28DE-446F-A402-7BE3C33A4B35"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4302:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6E1E4D8-B7F0-4BDB-B5A2-55436BEC85F1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4303:*:*:*:*:*:*" ,
"matchCriteriaId" : "59675CC4-8A5C-4668-908C-0886B4B310DC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4304:*:*:*:*:*:*" ,
"matchCriteriaId" : "45084336-F1DC-4E5B-A45E-506A779985D9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4305:*:*:*:*:*:*" ,
"matchCriteriaId" : "1B2CC071-5BB3-4A25-88F2-DBC56B94D895"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4306:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6FDF373-4711-4B72-A14E-CEB19301C40F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4307:*:*:*:*:*:*" ,
"matchCriteriaId" : "0E0F346C-0445-4D38-8583-3379962B540F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4308:*:*:*:*:*:*" ,
"matchCriteriaId" : "18B78BDC-0EAA-4781-8D62-01E47AA3BF40"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}