Zoho urges admins to patch severe ManageEngine bug immediately

by January 5, 2023

Business software provider Zoho has urged customers to patch a high-severity security flaw affecting multiple ManageEngine products.

The bug, tracked as CVE-2022-47523, is an SQL injection vulnerability found in the company’s Password Manager Pro secure vault, PAM360 privileged access management software, and Access Manager Plus privileged session management solution.

Successful exploitation provides authenticated attackers with access to the backend database and allows them to execute custom queries to access database table entries.

“We identified a SQL injection vulnerability (CVE-2022-47523) in our internal framework that would grant access to all [..] users to the backend database,” Zoho said.

The company added that “given the severity of this vulnerability, customers are strongly advised to upgrade to the latest build of PAM360, Password Manager Pro and Access Manager Plus immediately.”

Zoho says it fixed the issue last month by escaping special characters and adding proper validation.

To upgrade your installation, you should first download the latest upgrade pack for your product (PAM360Password Manager ProAccess Manager Plus).

The next step is to deploy the latest build according to the upgrade instructions available on each product’s Upgrade Pack page.

Product NameAffected VersionsFixed VersionFixed On
Password Manager Pro12200 and below1221030-12-2022
PAM3605800 and below580128-12-2022
Access Manager Plus4308 and below430929-12-2022

In September, CISA warned of another critical ManageEngine vulnerability (CVE-2022-35405) exploited in attacks to gain remote code execution on unpatched servers running PAM360, Access Manager Plus, and Password Manager Pro.

U.S. Federal Civilian Executive Branch Agencies (FCEB) agencies were given three weeks to patch vulnerable systems and ensure their networks would be protected from exploitation attempts.

Zoho ManageEngine servers have been under constant targeting in recent years, with Desktop Central instances, for instance, getting hacked and access to breached organizations’ networks sold on hacking forums starting in July 2020.

Between August and October 2021, nation-state hackers have also targeted ManageEngine servers using tactics and tooling similar to those of the Chinese-linked APT27 hacking group.

Following these extensive attack campaigns, the FBI and CISA issued two joint advisories [12] warning of state-sponsored attackers exploiting ManageEngine bugs to backdoor the networks of critical infrastructure organizations.


Update January 05, 15:30 EST: Article and title revised after Zoho downgraded the flaw’s severity rating from Critical to High.

“Unfortunately, our team had incorrectly marked the severity of the vulnerability as ‘Critical’ in one of our advisory posts and stated that the vulnerability could allow unauthenticated access to the database,” a Zoho spokesperson told BleepingComputer.

“The vulnerability could only be exploited by an authenticated user and the severity of the issue is ‘High’. We have updated our advisory posts to reflect this information.”

Would you like to get published on this Website? You can now email Uganda Times: an Opinion, any breaking news, Exposes, story ideas, human interest, articles or any interesting videos on: [email protected]. Or join the Ugandatimes WhatsApp Group or Telegram Channel for the latest updates

original ad 300

original ad 300

About

Trees and plants within cities help mitigate air pollution by absorbing carbon dioxide and releasing oxygen. They also act as natural air filters, trapping dust and particulate matter

Newsletter

Categories

Don't Miss

Uganda Ukraine Honorary Consulate

Uganda Hosts Ukraine’s Honorary Consulate to Strengthen Economic Ties

On February 13, 2026, Uganda marked…
Museveni US trade talks

Museveni US Trade Talks Focus on Restoring Bilateral Ties

President Yoweri Museveni has held high-level…