Breaking

IT teams and MSPs can be affected by ManageEngine security vulnerability

Zoho has urged its customers to patch a critical ManageEngine security vulnerability affecting multiple products.

The vulnerability is tracked as CVE-2022-47523 an SQL injection bug in the Password Manager Pro secure vault, Access Manager and PAM360 Privileged Access Management Software.

An exploitation of this ManageEngine security vulnerability allows attackers access backend database and execute queries on to table entries.

ManageEngine security vulnerability and the patch

ManageEngine security advisory mentioned “We identified a SQL injection vulnerability (CVE-2022-47523) in our internal framework that would grant access to all [..] users to the backend database.

Given the severity of this vulnerability, customers are strongly advised to upgrade to the latest build of PAM360, Password Manager Pro and Access Manager Plus immediately.”

ManageEngine has fixed the issue last month with correct validation. To update the installation, please download the latest patch for the product – PAM360, Password Manager Pro, Access Manager Plus.

Once downloaded the patch has to be deployed as per the instructions available on each product update page.

Since the vulnerability is severe, customers are highly recommended to update their build to the latest available version of PAM360, Access Manager Plus and Password Manager Pro ASAP.

Product NameAffected VersionsFixed VersionFixed On
Password Manager Pro12200 and below1221030-12-2022
PAM3605800 and below580128-12-2022
Access Manager Plus4308 and below430929-12-2022

Last year, CISA sent a warning on critical ManageEngine bugs that are being exploited in the wild for remote code execution on outdated servers with Access Manager Plus, Password Manager Pro and PAM360.

Why ManageEngine has been the sweet spot for threat actors?

ManageEngine has several IT products and is currently serving multiple geographic solutions with clients and partners making them a sweet spot for modern cyberattacks. ManageEngine security vulnerability and exploits only make things hassle-free for threat actors.

Starting with Desktop Central a.k.a Endpoint Central now, ServiceDesk Plus, and the above mentioned tools have been targeted for unpatched vulnerabilities in the recent years.

The widespread popularity and availability of servers at a poor security state is the key reason that hackers can easily manipulate and exploit ManageEngine solutions for breaching the network and extracting data. If not patches at the right time the IT teams and MSPs can become victim to a a major cyber incident.

A hacking maneuver of APT27 hacking group was imitated by other threat actors to breach ManageEngine servers last year on August and October.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, and Twitter.

You can reach out to us via Twitter/ Facebook or mail us at admin@thecybersecuritytimes.com for advertising requests.

Share the article with your friends
William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

Recent Posts

Top 5 Best Project Management Tools for Your Business

Explore efficiency with the Top 5 Best Project Management Software – streamline tasks, boost collaboration,…

2 months ago

Top 5 Best Free Antivirus for Android Smartphones: Stay Protected

Explore the top 5 best free antivirus apps for Android smartphones – your essential defense…

2 months ago

What is India’s Digital Personal Data Protection (DPDP)Act? Understanding Rights, Scope, Responsibilities, and Penalties

Unlocking India's DPDP Act: Your Guide to Rights, Responsibilities, and Top 5 Tools for 2024.…

3 months ago

Top 5 Best Data Loss Prevention Tools for 2024

Uncover insights on advanced features, performance, and user experiences. Discover the top 5 best Data…

3 months ago

Top 5 Windows Server Patching Tools for 2024

Unlock efficient Windows Server patching with insights on top tools and vendors. Streamline your cybersecurity…

3 months ago

Software Deployment: What it is, Best Practices and Top 5 Tools

Software deployment is the process of rolling out an application, which could occur manually or…

4 months ago