9.8

CVE-2022-47966

Warnung
Exploit

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4300
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4301
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4302
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4303
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4304
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4305
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4306
ZohocorpManageengine Access Manager Plus Version4.3 Updatebuild4307
ZohocorpManageengine Ad360 Version < 4.3
ZohocorpManageengine Ad360 Version4.3 Update4300
ZohocorpManageengine Ad360 Version4.3 Update4302
ZohocorpManageengine Ad360 Version4.3 Update4303
ZohocorpManageengine Ad360 Version4.3 Update4304
ZohocorpManageengine Ad360 Version4.3 Update4305
ZohocorpManageengine Ad360 Version4.3 Update4306
ZohocorpManageengine Ad360 Version4.3 Update4308
ZohocorpManageengine Ad360 Version4.3 Update4309
ZohocorpManageengine Adaudit Plus Version7.0 Update7000
ZohocorpManageengine Adaudit Plus Version7.0 Update7002
ZohocorpManageengine Adaudit Plus Version7.0 Update7003
ZohocorpManageengine Adaudit Plus Version7.0 Update7004
ZohocorpManageengine Adaudit Plus Version7.0 Update7005
ZohocorpManageengine Adaudit Plus Version7.0 Update7006
ZohocorpManageengine Adaudit Plus Version7.0 Update7007
ZohocorpManageengine Adaudit Plus Version7.0 Update7008
ZohocorpManageengine Adaudit Plus Version7.0 Update7050
ZohocorpManageengine Adaudit Plus Version7.0 Update7051
ZohocorpManageengine Adaudit Plus Version7.0 Update7052
ZohocorpManageengine Adaudit Plus Version7.0 Update7053
ZohocorpManageengine Adaudit Plus Version7.0 Update7054
ZohocorpManageengine Adaudit Plus Version7.0 Update7055
ZohocorpManageengine Adaudit Plus Version7.0 Update7060
ZohocorpManageengine Adaudit Plus Version7.0 Update7062
ZohocorpManageengine Adaudit Plus Version7.0 Update7063
ZohocorpManageengine Adaudit Plus Version7.0 Update7065
ZohocorpManageengine Adaudit Plus Version7.0 Update7080
ZohocorpManageengine Admanager Plus Version7.1 Update7100
ZohocorpManageengine Admanager Plus Version7.1 Update7101
ZohocorpManageengine Admanager Plus Version7.1 Update7102
ZohocorpManageengine Admanager Plus Version7.1 Update7110
ZohocorpManageengine Admanager Plus Version7.1 Update7111
ZohocorpManageengine Admanager Plus Version7.1 Update7112
ZohocorpManageengine Admanager Plus Version7.1 Update7113
ZohocorpManageengine Admanager Plus Version7.1 Update7114
ZohocorpManageengine Admanager Plus Version7.1 Update7115
ZohocorpManageengine Admanager Plus Version7.1 Update7116
ZohocorpManageengine Admanager Plus Version7.1 Update7117
ZohocorpManageengine Admanager Plus Version7.1 Update7118
ZohocorpManageengine Admanager Plus Version7.1 Update7120
ZohocorpManageengine Admanager Plus Version7.1 Update7121
ZohocorpManageengine Admanager Plus Version7.1 Update7122
ZohocorpManageengine Admanager Plus Version7.1 Update7123
ZohocorpManageengine Admanager Plus Version7.1 Update7124
ZohocorpManageengine Admanager Plus Version7.1 Update7125
ZohocorpManageengine Admanager Plus Version7.1 Update7126
ZohocorpManageengine Admanager Plus Version7.1 Update7130
ZohocorpManageengine Admanager Plus Version7.1 Update7131
ZohocorpManageengine Admanager Plus Version7.1 Update7140
ZohocorpManageengine Admanager Plus Version7.1 Update7141
ZohocorpManageengine Admanager Plus Version7.1 Update7150
ZohocorpManageengine Admanager Plus Version7.1 Update7151
ZohocorpManageengine Admanager Plus Version7.1 Update7160
ZohocorpManageengine Admanager Plus Version7.1 Update7161
ZohocorpManageengine Adselfservice Plus Version6.2 Update6200
ZohocorpManageengine Adselfservice Plus Version6.2 Update6201
ZohocorpManageengine Adselfservice Plus Version6.2 Update6202
ZohocorpManageengine Adselfservice Plus Version6.2 Update6203
ZohocorpManageengine Adselfservice Plus Version6.2 Update6204
ZohocorpManageengine Adselfservice Plus Version6.2 Update6205
ZohocorpManageengine Adselfservice Plus Version6.2 Update6206
ZohocorpManageengine Adselfservice Plus Version6.2 Update6207
ZohocorpManageengine Adselfservice Plus Version6.2 Update6208
ZohocorpManageengine Adselfservice Plus Version6.2 Update6209
ZohocorpManageengine Adselfservice Plus Version6.2 Update6210
ZohocorpManageengine Analytics Plus Version5.1 Update5100
ZohocorpManageengine Analytics Plus Version5.1 Update5110
ZohocorpManageengine Analytics Plus Version5.1 Update5120
ZohocorpManageengine Analytics Plus Version5.1 Update5121
ZohocorpManageengine Analytics Plus Version5.1 Update5130
ZohocorpManageengine Analytics Plus Version5.1 Update5140
ZohocorpManageengine Assetexplorer Version6.9 Update6900
ZohocorpManageengine Assetexplorer Version6.9 Update6901
ZohocorpManageengine Assetexplorer Version6.9 Update6902
ZohocorpManageengine Assetexplorer Version6.9 Update6903
ZohocorpManageengine Assetexplorer Version6.9 Update6904
ZohocorpManageengine Assetexplorer Version6.9 Update6905
ZohocorpManageengine Assetexplorer Version6.9 Update6906
ZohocorpManageengine Assetexplorer Version6.9 Update6907
ZohocorpManageengine Assetexplorer Version6.9 Update6908
ZohocorpManageengine Assetexplorer Version6.9 Update6909
ZohocorpManageengine Assetexplorer Version6.9 Update6950
ZohocorpManageengine Assetexplorer Version6.9 Update6951
ZohocorpManageengine Assetexplorer Version6.9 Update6952
ZohocorpManageengine Assetexplorer Version6.9 Update6953
ZohocorpManageengine Assetexplorer Version6.9 Update6954
ZohocorpManageengine Assetexplorer Version6.9 Update6955
ZohocorpManageengine Assetexplorer Version6.9 Update6956
ZohocorpManageengine Assetexplorer Version6.9 Update6957
ZohocorpManageengine Assetexplorer Version6.9 Update6970
ZohocorpManageengine Assetexplorer Version6.9 Update6971
ZohocorpManageengine Assetexplorer Version6.9 Update6972
ZohocorpManageengine Assetexplorer Version6.9 Update6973
ZohocorpManageengine Assetexplorer Version6.9 Update6974
ZohocorpManageengine Assetexplorer Version6.9 Update6975
ZohocorpManageengine Assetexplorer Version6.9 Update6976
ZohocorpManageengine Assetexplorer Version6.9 Update6977
ZohocorpManageengine Assetexplorer Version6.9 Update6978
ZohocorpManageengine Assetexplorer Version6.9 Update6979
ZohocorpManageengine Assetexplorer Version6.9 Update6980
ZohocorpManageengine Assetexplorer Version6.9 Update6981
ZohocorpManageengine Assetexplorer Version6.9 Update6982
ZohocorpManageengine Key Manager Plus Version6.4 Update6400
ZohocorpManageengine Pam360 Version < 5.7
ZohocorpManageengine Pam360 Version5.7 Updatebuild5700
ZohocorpManageengine Pam360 Version5.7 Updatebuild5710
ZohocorpManageengine Pam360 Version5.7 Updatebuild5711
ZohocorpManageengine Pam360 Version5.7 Updatebuild5712
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12100
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12101
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12110
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12120
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12121
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12122
ZohocorpManageengine Password Manager Pro Version12.1 Updatebuild12123
ZohocorpManageengine Servicedesk Plus Version14.0 Update14000
ZohocorpManageengine Servicedesk Plus Version14.0 Update14001
ZohocorpManageengine Servicedesk Plus Version14.0 Update14002
ZohocorpManageengine Servicedesk Plus Version14.0 Update14003
ZohocorpManageengine Servicedesk Plus Msp Version13.0 Update13000
ZohocorpManageengine Supportcenter Plus Version11.0 Update11017
ZohocorpManageengine Supportcenter Plus Version11.0 Update11018
ZohocorpManageengine Supportcenter Plus Version11.0 Update11019
ZohocorpManageengine Supportcenter Plus Version11.0 Update11020
ZohocorpManageengine Supportcenter Plus Version11.0 Update11021
ZohocorpManageengine Supportcenter Plus Version11.0 Update11022
ZohocorpManageengine Supportcenter Plus Version11.0 Update11024
ZohocorpManageengine Supportcenter Plus Version11.0 Update11025
ZohocorpManageengine Browser Security Plus Version < 11.1.2238.6
ZohocorpManageengine Device Control Plus Version < 10.1.2220.18
ZohocorpManageengine Endpoint Dlp Plus Version < 10.1.2137.6
ZohocorpManageengine Os Deployer Version < 1.1.2243.1
ZohocorpManageengine Patch Manager Plus Version < 10.1.2220.18
ZohocorpManageengine Remote Access Plus Version < 10.1.2228.11

23.01.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Schwachstelle

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.43% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.