Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_access_manager_plus | Zohocorp | * | 4.3 (excluding) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4300 (including) | 4.3-build4300 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4301 (including) | 4.3-build4301 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4302 (including) | 4.3-build4302 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4303 (including) | 4.3-build4303 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4304 (including) | 4.3-build4304 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4305 (including) | 4.3-build4305 (including) |
Manageengine_pam360 | Zohocorp | * | 5.7 (excluding) |
Manageengine_pam360 | Zohocorp | 5.7-build5700 (including) | 5.7-build5700 (including) |
Manageengine_pam360 | Zohocorp | 5.7-build5710 (including) | 5.7-build5710 (including) |
Manageengine_password_manager_pro | Zohocorp | * | 12.1 (excluding) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12100 (including) | 12.1-build12100 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12101 (including) | 12.1-build12101 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12110 (including) | 12.1-build12110 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12120 (including) | 12.1-build12120 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12121 (including) | 12.1-build12121 (including) |