CVE-2022-47966

CRITICALCVSS 9.8/10Actively ExploitedEPSS 99.75%

Last modified

CVE-2022-47966 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.75% chance of exploitation in the next 30 days.

Description

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.75%

100.0th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ZohocorpManageengine Access Manager Plus< 4.3
ZohocorpManageengine Access Manager Plus4.3Build4300
ZohocorpManageengine Ad360< 4.3
ZohocorpManageengine Ad3604.34300
ZohocorpManageengine Adaudit Plus< 7.0
ZohocorpManageengine Adaudit Plus7.07000
ZohocorpManageengine Admanager Plus< 7.1
ZohocorpManageengine Admanager Plus7.17100
ZohocorpManageengine Adselfservice Plus< 6.2
ZohocorpManageengine Adselfservice Plus6.26200
ZohocorpManageengine Analytics Plus< 5.1
ZohocorpManageengine Analytics Plus5.15100
ZohocorpManageengine Assetexplorer< 6.9
ZohocorpManageengine Assetexplorer6.96900
ZohocorpManageengine Key Manager Plus< 6.4
ZohocorpManageengine Key Manager Plus6.46400
ZohocorpManageengine Pam360< 5.7
ZohocorpManageengine Pam3605.7Build5700
ZohocorpManageengine Password Manager Pro< 12.1
ZohocorpManageengine Password Manager Pro12.1Build12100
ZohocorpManageengine Servicedesk Plus< 14.0
ZohocorpManageengine Servicedesk Plus14.014000
ZohocorpManageengine Servicedesk Plus Msp< 13.0
ZohocorpManageengine Servicedesk Plus Msp13.013000
ZohocorpManageengine Supportcenter Plus11.011017
ZohocorpManageengine Application Control Plus< 10.1.2220.18
ZohocorpManageengine Browser Security Plus< 11.1.2238.6
ZohocorpManageengine Device Control Plus< 10.1.2220.18
ZohocorpManageengine Endpoint Dlp Plus< 10.1.2137.6
ZohocorpManageengine Os Deployer< 1.1.2243.1
ZohocorpManageengine Patch Manager Plus< 10.1.2220.18
ZohocorpManageengine Remote Access Plus< 10.1.2228.11
ZohocorpManageengine Remote Monitoring And Management Central< 10.1.41
ZohocorpManageengine Vulnerability Manager Plus< 10.1.2220.18

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2022-47966?
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
How severe is CVE-2022-47966?
CVE-2022-47966 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 99.75% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2022-47966?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-47966?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST