CVE-2022-47966 vulnerability in Zoho Corp Products
Published on January 18, 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Known Exploited Vulnerability
This Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
The following remediation steps are recommended / required by February 13, 2023: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2022-47966 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Products Associated with CVE-2022-47966
You can be notified by stack.watch whenever vulnerabilities like CVE-2022-47966 are published in these products:
What versions are vulnerable to CVE-2022-47966?
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4300
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4301
- Zoho Corp Manageengine Access Manager Plus Fixed in Version 4.3
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4302
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4303
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4304
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4305
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4306
- Zoho Corp Manageengine Access Manager Plus Version 4.3 build4307
- Zoho Corp Manageengine Ad360 Fixed in Version 4.3
- Zoho Corp Manageengine Ad360 Version 4.3 4300
- Zoho Corp Manageengine Ad360 Version 4.3 4302
- Zoho Corp Manageengine Ad360 Version 4.3 4303
- Zoho Corp Manageengine Ad360 Version 4.3 4304
- Zoho Corp Manageengine Ad360 Version 4.3 4305
- Zoho Corp Manageengine Ad360 Version 4.3 4306
- Zoho Corp Manageengine Ad360 Version 4.3 4308
- Zoho Corp Manageengine Ad360 Version 4.3 4309
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7002
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7003
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7004
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7005
- Zoho Corp Manageengine Adaudit Plus Fixed in Version 7.0
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7000
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7006
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7007
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7008
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7050
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7051
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7052
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7053
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7054
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7055
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7060
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7062
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7063
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7065
- Zoho Corp Manageengine Adaudit Plus Version 7.0 7080
- Zoho Corp Manageengine Admanager Plus Version 7.1 7100
- Zoho Corp Manageengine Admanager Plus Version 7.1 7101
- Zoho Corp Manageengine Admanager Plus Fixed in Version 7.1
- Zoho Corp Manageengine Admanager Plus Version 7.1 7102
- Zoho Corp Manageengine Admanager Plus Version 7.1 7110
- Zoho Corp Manageengine Admanager Plus Version 7.1 7111
- Zoho Corp Manageengine Admanager Plus Version 7.1 7112
- Zoho Corp Manageengine Admanager Plus Version 7.1 7113
- Zoho Corp Manageengine Admanager Plus Version 7.1 7114
- Zoho Corp Manageengine Admanager Plus Version 7.1 7115
- Zoho Corp Manageengine Admanager Plus Version 7.1 7116
- Zoho Corp Manageengine Admanager Plus Version 7.1 7117
- Zoho Corp Manageengine Admanager Plus Version 7.1 7118
- Zoho Corp Manageengine Admanager Plus Version 7.1 7120
- Zoho Corp Manageengine Admanager Plus Version 7.1 7121
- Zoho Corp Manageengine Admanager Plus Version 7.1 7122
- Zoho Corp Manageengine Admanager Plus Version 7.1 7123
- Zoho Corp Manageengine Admanager Plus Version 7.1 7124
- Zoho Corp Manageengine Admanager Plus Version 7.1 7125
- Zoho Corp Manageengine Admanager Plus Version 7.1 7126
- Zoho Corp Manageengine Admanager Plus Version 7.1 7130
- Zoho Corp Manageengine Admanager Plus Version 7.1 7131
- Zoho Corp Manageengine Admanager Plus Version 7.1 7140
- Zoho Corp Manageengine Admanager Plus Version 7.1 7141
- Zoho Corp Manageengine Admanager Plus Version 7.1 7150
- Zoho Corp Manageengine Admanager Plus Version 7.1 7151
- Zoho Corp Manageengine Admanager Plus Version 7.1 7160
- Zoho Corp Manageengine Admanager Plus Version 7.1 7161
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6201
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6202
- Zoho Corp Manageengine Adselfservice Plus Fixed in Version 6.2
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6200
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6203
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6204
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6205
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6206
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6207
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6208
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6209
- Zoho Corp Manageengine Adselfservice Plus Version 6.2 6210
- Zoho Corp Manageengine Analytics Plus Fixed in Version 5.1
- Zoho Corp Manageengine Analytics Plus Version 5.1 5100
- Zoho Corp Manageengine Analytics Plus Version 5.1 5110
- Zoho Corp Manageengine Analytics Plus Version 5.1 5120
- Zoho Corp Manageengine Analytics Plus Version 5.1 5121
- Zoho Corp Manageengine Analytics Plus Version 5.1 5130
- Zoho Corp Manageengine Analytics Plus Version 5.1 5140
- Zoho Corp Manageengine Assetexplorer Version 6.9 6900
- Zoho Corp Manageengine Assetexplorer Version 6.9 6901
- Zoho Corp Manageengine Assetexplorer Version 6.9 6902
- Zoho Corp Manageengine Assetexplorer Version 6.9 6903
- Zoho Corp Manageengine Assetexplorer Version 6.9 6904
- Zoho Corp Manageengine Assetexplorer Version 6.9 6905
- Zoho Corp Manageengine Assetexplorer Version 6.9 6906
- Zoho Corp Manageengine Assetexplorer Version 6.9 6907
- Zoho Corp Manageengine Assetexplorer Version 6.9 6908
- Zoho Corp Manageengine Assetexplorer Version 6.9 6909
- Zoho Corp Manageengine Assetexplorer Version 6.9 6950
- Zoho Corp Manageengine Assetexplorer Version 6.9 6951
- Zoho Corp Manageengine Assetexplorer Version 6.9 6952
- Zoho Corp Manageengine Assetexplorer Version 6.9 6953
- Zoho Corp Manageengine Assetexplorer Version 6.9 6954
- Zoho Corp Manageengine Assetexplorer Version 6.9 6955
- Zoho Corp Manageengine Assetexplorer Version 6.9 6956
- Zoho Corp Manageengine Assetexplorer Version 6.9 6957
- Zoho Corp Manageengine Assetexplorer Version 6.9 6970
- Zoho Corp Manageengine Assetexplorer Version 6.9 6971
- Zoho Corp Manageengine Assetexplorer Version 6.9 6972
- Zoho Corp Manageengine Assetexplorer Version 6.9 6973
- Zoho Corp Manageengine Assetexplorer Version 6.9 6974
- Zoho Corp Manageengine Assetexplorer Version 6.9 6975
- Zoho Corp Manageengine Assetexplorer Version 6.9 6976
- Zoho Corp Manageengine Assetexplorer Fixed in Version 6.9
- Zoho Corp Manageengine Assetexplorer Version 6.9 6980
- Zoho Corp Manageengine Assetexplorer Version 6.9 6979
- Zoho Corp Manageengine Assetexplorer Version 6.9 6978
- Zoho Corp Manageengine Assetexplorer Version 6.9 6977
- Zoho Corp Manageengine Assetexplorer Version 6.9 6981
- Zoho Corp Manageengine Assetexplorer Version 6.9 6982
- Zoho Corp Manageengine Key Manager Plus Fixed in Version 6.4
- Zoho Corp Manageengine Key Manager Plus Version 6.4 6400
- Zoho Corp Manageengine Pam360 Version 5.7 build5710
- Zoho Corp Manageengine Pam360 Version 5.7 build5700
- Zoho Corp Manageengine Pam360 Fixed in Version 5.7
- Zoho Corp Manageengine Pam360 Version 5.7 build5711
- Zoho Corp Manageengine Pam360 Version 5.7 build5712
- Zoho Corp Manageengine Password Manager Pro Fixed in Version 12.1
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12100
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12110
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12120
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12101
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12121
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12122
- Zoho Corp Manageengine Password Manager Pro Version 12.1 build12123
- Zoho Corp Manageengine Servicedesk Plus Fixed in Version 14.0
- Zoho Corp Manageengine Servicedesk Plus Version 14.0 14000
- Zoho Corp Manageengine Servicedesk Plus Version 14.0 14001
- Zoho Corp Manageengine Servicedesk Plus Version 14.0 14002
- Zoho Corp Manageengine Servicedesk Plus Version 14.0 14003
- Zoho Corp Manageengine Servicedesk Plus Msp Fixed in Version 13.0
- Zoho Corp Manageengine Servicedesk Plus Msp Version 13.0 13000
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11017
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11018
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11019
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11021
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11020
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11022
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11024
- Zoho Corp Manageengine Supportcenter Plus Version 11.0 11025
- Zoho Corp Manageengine Browser Security Plus Fixed in Version 11.1.2238.6
- Zoho Corp Manageengine Device Control Plus Fixed in Version 10.1.2220.18
- Zoho Corp Manageengine Endpoint Dlp Plus Fixed in Version 10.1.2137.6
- Zoho Corp Manageengine Os Deployer Fixed in Version 1.1.2243.1
- Zoho Corp Manageengine Patch Manager Plus Fixed in Version 10.1.2220.18
- Zoho Corp Manageengine Remote Access Plus Fixed in Version 10.1.2228.11
- Zoho Corp Manageengine Manager Plus Fixed in Version 10.1.2220.18
- Zoho Corp Manageengine Remote Monitoring Management Central Fixed in Version 10.1.41
- Zoho Corp Manageengine Application Control Plus Fixed in Version 10.1.220.18