Cyber Resilience

CVE-2022-47523

SQLi in Zohocorp Manageengine Access Manager Plus ≤ 4.3

High EPSSSQLiXSS
Published
05 January 2023
Modified
09 April 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.71 99.3th percentile
Risk Priority 96 floored blend · peak EPSS

Summary

CVE-2022-47523 is a critical-severity SQL Injection (CWE-89) vulnerability in Zohocorp Manageengine Access Manager Plus. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Zoho ManageEngine Access Manager Plus before version 4309, Password Manager Pro before 12210, and PAM360 before 5801 contain a SQL injection vulnerability tracked as CVE-2022-47523. The issue is also associated with CWE-89 and CWE-79 and carries a CVSS 3.1 base score of 9.8 reflecting network attack vector, low complexity, and no required privileges or user interaction.

An unauthenticated remote attacker can supply crafted input to exploit the flaw and obtain full read, write, and disruption capabilities over the affected installation. The same vector may additionally enable cross-site scripting behavior consistent with the listed CWEs.

Vendor advisories published at https://www.manageengine.com/privileged-session-management/advisory/cve-2022-47523.html direct customers to apply the corrected releases (Access Manager Plus 4309, Password Manager Pro 12210, and PAM360 5801) to eliminate the injection paths. The associated EPSS score reached a peak of 0.5828 before receding to its current value of 0.4555.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
Unauthenticated SQL injection in a public-facing privileged access management web application directly enables remote exploitation for initial access.
T1059 Command and Scripting Interpreter Executionconfidence: MEDIUM
Successful exploitation grants arbitrary read/write access that can be used to execute commands or scripts on the server.
T1505.003 Web Shell Persistenceconfidence: MEDIUM
Full control over the web application allows an attacker to implant a web shell for persistent remote access.
T1213.006 Databases Collectionconfidence: HIGH
SQL injection provides direct access to the backend database, enabling collection of stored credentials and configuration data.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-28341Same product class: network monitoring / SIEM
CVE-2023-23077Same product class: network monitoring / SIEM
CVE-2023-38331Same product class: network monitoring / SIEM
CVE-2023-37308Same product class: network monitoring / SIEM
CVE-2023-23073Same product class: network monitoring / SIEM
CVE-2023-23074Same product class: network monitoring / SIEM
CVE-2023-23078Same product class: network monitoring / SIEM
CVE-2023-29442Same product class: network monitoring / SIEM
CVE-2023-23075Same product class: network monitoring / SIEM
CVE-2023-38333Same product class: network monitoring / SIEM

Affected Assets

zohocorp
manageengine password manager pro
12.2 · ≤ 12.2
zohocorp
manageengine pam360
5.8 · ≤ 5.8
zohocorp
manageengine access manager plus
4.3 · ≤ 4.3

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • SI-10 Information Input Validation
  • SI-2 Flaw Remediation
Detect
Catch it (NIST detect / respond)
  • SI-4 System Monitoring
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.1.2
  • V1.3.2
  • V6.2.5

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires validation of all inputs to block crafted SQL payloads that exploit the unauthenticated injection flaw in ManageEngine.

prevent

Mandates timely application of vendor patches (4309/12210/5801) that close the documented SQL injection paths before exploitation.

detect

Enables continuous monitoring and anomaly detection on database queries or web requests that could indicate successful or attempted SQL injection.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly target injection flaws during coding and review so largely prevent CWE-89 introduction, yet the single broad outcome leaves residual risk from incomplete neutralization techniques or missed edge cases.

PR.AT-02 partial match
prevents

Training raises developer awareness of SQLi risks and can reduce introduction likelihood (partial) but removes none of the actual coding flaw's risk by itself since technical neutralization is still required.

PR.PS-02 partial match
prevents

Patching and EOL replacement can remediate known XSS instances in libraries or frameworks (partial) but do nothing to enforce input neutralization in application code (none).

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

The same secure-coding and static-analysis activities surface missing neutralization of SQL metacharacters before the system is accepted.

prevents

Early warnings and shared best-practice information help organizations apply the latest remediation techniques against SQL-injection vulnerabilities.

prevents

Threat-intelligence feeds that surface new SQL-injection campaigns enable rapid updates to query-construction defenses and detection signatures before exploitation occurs.

prevents

Secure-coding rules and security testing phases mandate the use of parameterized queries or equivalent escaping, preventing the construction of dynamic SQL statements from untrusted input.

prevents

Language-specific secure coding rules, peer review and SAST together prevent the construction of SQL statements from untrusted data without proper parameterization or escaping.

none

Webpage malware scanning and block-listing of known malicious sites reduce the likelihood that reflected or stored script payloads reach a user’s browser.

References