Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Zoho:ManageEngine
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2022-47966 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html; reference
- http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.html Exploit
- http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.html Exploit
- http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.html Exploit
- https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysis Exploit
- https://blog.viettelcybersecurity.com/saml-show-stopper/ Exploit
- https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6 Release Notes
- https://github.com/horizon3ai/CVE-2022-47966 Third Party Advisory
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a Third Party Advisory
- https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/ Exploit
- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html Patch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47966 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD