
Cloud Vulnerability DB
A community-led vulnerabilities database
Zohocorp ManageEngine PAM360 version 6601 contains an authorization vulnerability that allows low-privileged users to perform administrative actions. This vulnerability specifically affects only the PAM360 6600 version, with no other versions being impacted (NVD CVE).
The vulnerability was discovered by ManageEngine's internal security team and received a CVSS v3.1 base score of 8.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. The vulnerability is classified as CWE-863 (Incorrect Authorization) and allows unauthorized access through crafted requests to the PAM360 server (Vendor Advisory).
When exploited, this vulnerability enables non-administrative users to perform privileged operations by sending crafted requests to the PAM360 server, potentially compromising the security of the system (Vendor Advisory).
The vulnerability can be exploited by non-admin users who have access to the system by sending specially crafted requests to the PAM360 server. Given the high severity rating and the relatively low complexity of exploitation, the risk is considered significant (Vendor Advisory).
ManageEngine has released version 6601 on April 10, 2024, which addresses this vulnerability. Users are strongly advised to upgrade to the latest build immediately. The upgrade can be performed by downloading the latest upgrade pack from the official ManageEngine website and following the provided installation instructions (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."