
Cloud Vulnerability DB
A community-led vulnerabilities database
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by an authenticated SQL Injection vulnerability that can be exploited via a global search option. The vulnerability was reported on June 5, 2024, and was patched on June 14, 2024. This high-severity vulnerability has been assigned CVE-2024-5546 with a CVSS v3.1 base score of 8.8 (NVD).
The vulnerability is classified as SQL Injection (CWE-89), allowing authenticated users to execute custom queries and access database table entries through the vulnerable global search functionality. The CVSS v3.1 vector string is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and requiring low privileges with no user interaction (NVD, Vendor Advisory).
While the vulnerability allows attackers to execute custom queries and access database table entries, the dual encryption mechanism implemented in the affected products ensures that access to sensitive information like passwords remains restricted. Despite this protection mechanism, the vulnerability is still rated as high severity due to its potential impact on system security (Vendor Advisory).
The vulnerability requires authentication to exploit, making it somewhat limited in scope. However, once authenticated, an attacker can leverage the global search option to execute SQL injection attacks. The low attack complexity and network vector make this vulnerability relatively straightforward to exploit for authenticated users (NVD).
ManageEngine has released patches to address this vulnerability. Users of Password Manager Pro should upgrade to version 12431 or later, while PAM360 users should upgrade to version 7001 or later. The vendor strongly advises immediate upgrade given the severity of the vulnerability. Patches can be obtained through the official upgrade packs available from ManageEngine (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."