Umbra Wiki cve cve/CVE-2022-47966
Back to wiki

CVE-2022-47966 — Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2022-47966

CVE-2022-47966: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Zoho
Product ManageEngine
Date added 2023-01-23
Due date 2023-02-13
Ransomware campaign use Known

Description

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html; https://nvd.nist.gov/vuln/detail/CVE-2022-47966

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-47966
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog