CVE-2022-47966
CRITICALCVSS 9.8Known ExploitedCISA Known Exploited Vulnerability
https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html; https://nvd.nist.gov/vuln/detail/CVE-2022-47966
Remediation deadline: February 13, 2023
Ransomware use: Known
Description
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
Timeline
Published:January 18th, 2023 6:15 PM
Last modified:July 31st, 2026 4:16 AM
Added to KEV:January 23rd, 2023
CVSS Scoring
CVSS v3: 9.8 (CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
From NVD CPE configuration data
Vendors
zohocorp
Products
manageengine_access_manager_plusmanageengine_ad360manageengine_adaudit_plusmanageengine_admanager_plusmanageengine_adselfservice_plusmanageengine_analytics_plusmanageengine_assetexplorermanageengine_key_manager_plusmanageengine_pam360manageengine_password_manager_promanageengine_servicedesk_plusmanageengine_servicedesk_plus_mspmanageengine_supportcenter_plusmanageengine_application_control_plusmanageengine_browser_security_plusmanageengine_device_control_plusmanageengine_endpoint_dlp_plusmanageengine_os_deployermanageengine_patch_manager_plusmanageengine_remote_access_plus
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
- http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.htmlExploit
- https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysisExploit
- https://blog.viettelcybersecurity.com/saml-show-stopper/Exploit
- https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6Release Notes
- https://github.com/horizon3ai/CVE-2022-47966Third Party Advisory
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250aThird Party Advisory
- https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/Exploit
- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.htmlPatch
- http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.htmlExploit
- https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysisExploit
- https://blog.viettelcybersecurity.com/saml-show-stopper/Exploit
- https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6Release Notes
- https://github.com/horizon3ai/CVE-2022-47966Third Party Advisory
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250aThird Party Advisory
- https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/Exploit
- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.htmlPatch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47966US Government Resource
Source: NIST NVD · Data may lag official sources by up to one minute