CVE-2022-47966 is a critical remote code execution (RCE) vulnerability affecting numerous Zoho ManageEngine on-premise products, including ServiceDesk Plus, ADManager Plus, and Endpoint Central, stemming from insecure handling of XSLT features in an outdated Apache Santuario xmlsec library. This flaw allows unauthenticated attackers to execute arbitrary code if SAML SSO has ever been configured for the product. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including by nation-state threat actors and ransomware campaigns, with public Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4300:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4301:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4302:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4303:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.