CVE-2023-2291
Zoho ManageEngine Access Manager Plus vulnerability analysis and mitigation

Overview

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, identified as CVE-2023-2291. The vulnerability affects multiple ManageEngine products including Access Manager Plus, Password Manager Pro, and PAM360. This security issue was discovered and disclosed to the vendor on January 23, 2023, with the public disclosure occurring on April 25, 2023 (Tenable Research).

Technical details

The vulnerability involves hardcoded PostgreSQL credentials that allow access to the database server running under the SYSTEM account. The CVSSv3 Base Score is 8.8 (High) with a temporal score of 8.3, and a vector of AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The PostgreSQL database server used in AMP runs with SYSTEM privileges, though with limited administrative capabilities (Tenable Research).

Impact

The vulnerability allows a malicious actor with low-level privileges to modify configuration data and escalate their permissions to Administrative user level. Through the exploitation of these hardcoded credentials, an attacker can manipulate the AMP configuration files and execute arbitrary code under the security context of the AMP service (Tenable Research).

Mitigation and workarounds

As of the initial disclosure, no vendor-supplied solution was available. Users are advised to contact ManageEngine support for mitigation assistance. The vendor acknowledged the vulnerability and indicated that patches were in development, though they were not ready for release at the time of disclosure (Tenable Research).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Access Manager Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-47966CRITICAL9.8
  • Zoho ManageEngine ServiceDesk Plus logoZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
YesYesJan 18, 2023
CVE-2022-47523CRITICAL9.8
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 05, 2023
CVE-2025-11669HIGH8.1
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 13, 2026
CVE-2023-2291HIGH7.8
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesApr 26, 2023
CVE-2023-6105MEDIUM5.5
  • Zoho ManageEngine ServiceDesk Plus logoZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_patch_connect_plus
NoYesNov 15, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management