Executive brief
Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus are vulnerable to remote code execution due to a Java deserialization flaw in the XML-RPC interface. The vulnerability allows unauthenticated attackers to execute arbitrary code on Password Manager Pro and PAM360, while Access Manager Plus requires authentication for exploitation.
Affected products
- Zoho ManageEngine Password Manager Pro before 12101
- Zoho ManageEngine PAM360 before 5510
- Zoho ManageEngine Access Manager Plus before 4303
Timeline
- 2022-07-19: disclosed: NVD Published Date
- 2022-09-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-07-19: patched: Vendor advisory and patches released
- 2022-09-22: exploited: Reported as exploited in the wild per CISA KEV entry date