📦 Manageengine Access Manager Plus

by Zohocorp

🔍 What is Manageengine Access Manager Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-35405

CRITICAL CVSS 9.8 Jul 19, 2022

This vulnerability allows unauthenticated attackers to execute arbitrary code on Zoho ManageEngine Password Manager Pro and PAM360 systems through Java deserialization in XML-RPC endpoints. It also af...

CVE-2022-29081

CRITICAL CVSS 9.8 Apr 28, 2022

This vulnerability allows attackers to bypass access controls on specific REST API endpoints in Zoho ManageEngine products by using '../RestAPI' in URLs. Affected organizations using vulnerable versio...

CVE-2021-44676

CRITICAL CVSS 9.8 Dec 20, 2021

CVE-2021-44676 is an authentication bypass vulnerability in Zoho ManageEngine Access Manager Plus that allows unauthenticated attackers to view sensitive data and modify application settings. This aff...

CVE-2025-11669

HIGH CVSS 8.1 Jan 13, 2026

This vulnerability allows attackers to bypass authorization controls in ManageEngine's privileged access management products when initiating remote sessions. Attackers could gain unauthorized access t...

CVE-2023-2291

HIGH CVSS 7.8 Apr 26, 2023

This vulnerability involves hardcoded static credentials in PostgreSQL data used by ManageEngine Access Manager Plus, Password Manager Pro, and PAM360. Attackers can exploit these credentials to modif...