Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2024-5546
Disclosure Date: August 28, 2024 (last updated September 20, 2024)
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
0
Attacker Value
Unknown
CVE-2022-47523
Disclosure Date: January 05, 2023 (last updated October 08, 2023)
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2020-7962
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
0