Impact
This vulnerability is an authenticated SQL injection that allows an attacker with valid credentials to read, modify, delete or potentially execute malicious code against the database that backs ManageEngine products. The injection gives the attacker full control over stored data and could compromise the confidentiality, integrity, and availability of the system.
Affected Systems
Zohocorp’s ManageEngine Access Manager Plus versions earlier than 4405, PAM360 versions earlier than 8561, and Password Manager Pro versions earlier than 13235 are affected.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. Exploitation requires legitimate authentication, suggesting the threat is most acute from internal users or compromised credentials. The EPSS score is not provided and the flaw is not listed in the CISA KEV catalog, but the high CVSS and authentication requirement indicate a significant risk of data breach if an attacker gains authorized access.
OpenCVE Enrichment