CVE-2022-47966
About
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Rainforest analyst review
The root cause is a shared, outdated copy of the Apache Santuario xmlsec library (1.4.1) bundled across dozens of Zoho ManageEngine products. In that version the XSLT transform features leave certain security protections up to the calling application, and ManageEngine never implemented them. When a product validates a SAML SSO response, an attacker can embed a malicious XSLT transform in the signed XML; the library processes it and executes attacker-supplied code, giving an unauthenticated remote actor arbitrary command execution on the server. Exploitation only works where SAML SSO has been configured at some point, which is common in enterprise deployments.
The scope is what makes this dangerous: ServiceDesk Plus, Password Manager Pro, ADSelfService Plus, Endpoint Central and many others are IT-management and identity tools that hold privileged credentials and reach deep into the estate. A public exploit landed quickly and multiple threat actors, including state-aligned groups, used it for initial access and follow-on intrusion. Because one library affects the whole product line, inventory every ManageEngine instance, patch to the fixed builds listed by Zoho, and hunt for post-exploitation activity on any host where SAML SSO was ever enabled.
References
- http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.html
- https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysis
- https://blog.viettelcybersecurity.com/saml-show-stopper/
- https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6
- https://github.com/horizon3ai/CVE-2022-47966
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a
- https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47966
Related CVEs
Frequently asked questions
What is CVE-2022-47966?
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections.
How severe is CVE-2022-47966?
CVE-2022-47966 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-47966 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-47966?
Public advisories list the following as affected: manageengine access manager plus, manageengine ad360, manageengine adaudit plus, manageengine admanager plus, manageengine adselfservice plus, manageengine analytics plus, +16. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-47966?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
