CVE-2022-47966: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Other sources
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine products (Apache Santuario xmlsec dependency)to a version that resolves this vulnerability.Fixed in 14004 - Upgrade
Upgrade
Zoho ManageEngine ServiceDesk Plus MSPto a version that resolves this vulnerability.Fixed in 13001 - Upgrade
Upgrade
Zoho ManageEngine SupportCenter Plusto a version that resolves this vulnerability.Fixed in 11026 - Upgrade
Upgrade
Zoho ManageEngine Vulnerability Manager Plusto a version that resolves this vulnerability.Fixed in 10.1.2220.18 - Upgrade
Upgrade
Zoho ManageEngine Access Manager Plusto a version that resolves this vulnerability.Fixed in 4308 - Upgrade
Upgrade
Zoho ManageEngine Active Directoryto a version that resolves this vulnerability.Fixed in 360 - Upgrade
Upgrade
Zoho ManageEngine ADAudit Plusto a version that resolves this vulnerability.Fixed in 7081 - Upgrade
Upgrade
Zoho ManageEngine ADManager Plusto a version that resolves this vulnerability.Fixed in 7162 - Upgrade
Upgrade
Zoho ManageEngine ADSelfService Plusto a version that resolves this vulnerability.Fixed in 6211 - Upgrade
Upgrade
Zoho ManageEngine Analytics Plusto a version that resolves this vulnerability.Fixed in 5150 - Upgrade
Upgrade
Zoho ManageEngine Application Control Plusto a version that resolves this vulnerability.Fixed in 10.1.2220.18 - Upgrade
Upgrade
Zoho ManageEngine Asset Explorerto a version that resolves this vulnerability.Fixed in 6983 - Upgrade
Upgrade
Zoho ManageEngine Browser Security Plusto a version that resolves this vulnerability.Fixed in 11.1.2238.6 - Upgrade
Upgrade
Zoho ManageEngine Device Control Plusto a version that resolves this vulnerability.Fixed in 10.1.2220.18 - Upgrade
Upgrade
Zoho ManageEngine Endpoint Centralto a version that resolves this vulnerability.Fixed in 10.1.2228.11 - Upgrade
Upgrade
Zoho ManageEngine Endpoint Central MSPto a version that resolves this vulnerability.Fixed in 10.1.2228.11 - Upgrade
Upgrade
Zoho ManageEngine Endpoint DLPto a version that resolves this vulnerability.Fixed in 10.1.2137.6 - Upgrade
Upgrade
Zoho ManageEngine Key Manager Plusto a version that resolves this vulnerability.Fixed in 6401 - Upgrade
Upgrade
Zoho ManageEngine OS Deployerto a version that resolves this vulnerability.Fixed in 1.1.2243.1 - Upgrade
Upgrade
Zoho ManageEngine PAM 360to a version that resolves this vulnerability.Fixed in 5713 - Upgrade
Upgrade
Zoho ManageEngine Password Manager Proto a version that resolves this vulnerability.Fixed in 12124 - Upgrade
Upgrade
Zoho ManageEngine Patch Manager Plusto a version that resolves this vulnerability.Fixed in 10.1.2220.18 - Upgrade
Upgrade
Zoho ManageEngine Remote Access Plusto a version that resolves this vulnerability.Fixed in 10.1.2228.11 - Upgrade
Upgrade
Zoho ManageEngine Remote Monitoring and Management (RMM)to a version that resolves this vulnerability.Fixed in 10.1.41 - Configuration
Ensure SAML SSO is not configured for the product; for products where exploitation requires SAML SSO to be currently active, ensure SAML SSO is not active.
Zoho ManageEngine SAML SSO configuration SAML SSO (has ever been configured / currently active) = Not configured or not active
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47966?
CVE-2022-47966 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2022-47966?
To fix CVE-2022-47966, update Zoho ManageEngine products to versions that address this vulnerability, specifically those patched after the affected versions.
Which products are affected by CVE-2022-47966?
CVE-2022-47966 affects multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus, Access Manager Plus, and ADAudit Plus, among others.
What type of vulnerability is CVE-2022-47966?
CVE-2022-47966 is classified as a remote code execution vulnerability.
Where can I find more information about CVE-2022-47966?
Detailed information about CVE-2022-47966 can typically be found in the official CVE database and vendor security advisories.