Impact
An improper validation of SAML assertions in ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8551 allows an attacker to bypass authentication. The flaw permits the submission of forged SAML tokens that are accepted by the service provider without verifying the issuer or signature, enabling unauthorized access to the application and its protected resources. This weakness falls under CWE‑347, which involves invalid authentication leading to compromised credentials.
Affected Systems
ManageEngine PAM360 (Zohocorp) versions earlier than 8551 and ManageEngine Password Manager Pro (Zohocorp) versions earlier than 13232 are affected. These products expose organizations to risk when SAML configuration is not properly validated.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the likely attack vector is forging a SAML assertion or manipulating the response from an impersonated or compromised identity provider. Based on the description, it is inferred that the attacker can generate a valid assertion that bypasses authentication without requiring direct access to an existing identity provider. Once accepted, the attacker gains full authentication, enabling unrestricted access to protected resources and potential privilege escalation.
OpenCVE Enrichment