Zoho Addresses SQL Injection Vulnerability in ManageEngine Products

Threat Level – Amber | Vulnerability Report
Download PDF

A security flaw affecting multiple ManageEngine products identified as CVE-2022-47523 is an SQL injection vulnerability found in the ZOHO’s Password Manager Pro Secure Vault, PAM360 Privileged Access Management Software, and Access Manager Plus Privileged Session Management Solution. If exploited, the vulnerability would allow attackers to gain unauthenticated access to the backend database and execute custom queries to access database table entries. Zoho has fixed the issue and is urging customers to upgrade to the latest builds of the affected products immediately.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs