Junglewise Threat Intelligence

CVE-2022-35405: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

CVE-2022-35405 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-09-22

Technologies: Zoho ManageEngine. Vendors: Zoho.

Executive brief

Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus are vulnerable to remote code execution due to a Java deserialization flaw in the XML-RPC interface. The vulnerability allows unauthenticated attackers to execute arbitrary code on Password Manager Pro and PAM360, while Access Manager Plus requires authentication for exploitation.

Affected products

  • Zoho ManageEngine Password Manager Pro before 12101
  • Zoho ManageEngine PAM360 before 5510
  • Zoho ManageEngine Access Manager Plus before 4303

Timeline

  • 2022-07-19: disclosed: NVD Published Date
  • 2022-09-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-07-19: patched: Vendor advisory and patches released
  • 2022-09-22: exploited: Reported as exploited in the wild per CISA KEV entry date

Related threats