Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_pam360 | Zohocorp | 4.0 (including) | 4.0 (including) |
Manageengine_pam360 | Zohocorp | 4.0-build4001 (including) | 4.0-build4001 (including) |
Manageengine_pam360 | Zohocorp | 4.0-build4002 (including) | 4.0-build4002 (including) |
Manageengine_pam360 | Zohocorp | 4.1 (including) | 4.1 (including) |
Manageengine_pam360 | Zohocorp | 4.1-build4100 (including) | 4.1-build4100 (including) |
Manageengine_pam360 | Zohocorp | 4.1-build4101 (including) | 4.1-build4101 (including) |
Manageengine_pam360 | Zohocorp | 4.5 (including) | 4.5 (including) |
Manageengine_pam360 | Zohocorp | 4.5-build4500 (including) | 4.5-build4500 (including) |
Manageengine_pam360 | Zohocorp | 4.5-build4501 (including) | 4.5-build4501 (including) |
Manageengine_pam360 | Zohocorp | 5.0 (including) | 5.0 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5000 (including) | 5.0-build5000 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5001 (including) | 5.0-build5001 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5002 (including) | 5.0-build5002 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5003 (including) | 5.0-build5003 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5004 (including) | 5.0-build5004 (including) |
Manageengine_pam360 | Zohocorp | 5.1 (including) | 5.1 (including) |
Manageengine_pam360 | Zohocorp | 5.1-build5100 (including) | 5.1-build5100 (including) |
Manageengine_pam360 | Zohocorp | 5.2 (including) | 5.2 (including) |
Manageengine_pam360 | Zohocorp | 5.2-build5200 (including) | 5.2-build5200 (including) |
Manageengine_pam360 | Zohocorp | 5.3 (including) | 5.3 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5300 (including) | 5.3-build5300 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5301 (including) | 5.3-build5301 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5302 (including) | 5.3-build5302 (including) |