CVE-2022-47966
CVE-2022-47966 is a critical remote code execution vulnerability in multiple Zoho ManageEngine products. It arises from improper security protections in Apache Santuario xmlsec 1.4.1, allowing attackers to execute code if SAML SSO is configured. Exploitation requires prior SAML SSO setup for some products.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Zoho ManageEngine on-premise products listed in the CPE, including ServiceDesk Plus, Active Directory 360, ADAudit Plus, and others, up to specific versions (e.g., ServiceDesk Plus 14003, AD360 4.3).
Real-world impact
High risk of remote code execution if SAML SSO is configured. Exploitation is possible without user interaction.
Why this severity
CVSS 9.8 (critical): High confidence in exploitability and potential for full system compromise.
What to do about it
- 01Apply the vendor's security updates or patches as instructed in their advisory for affected products.
- 02Verify updates are installed across all affected systems, especially those using SAML SSO.
CISA KEV required action
Timeline
- Jan 18, 2023 · Jan 18, 2023PublishedDisclosed and added to the National Vulnerability Database.
- Jan 23, 2023 · Jan 23, 2023Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Feb 13, 2023 · Feb 13, 2023CISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 31, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 31, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- packetstormsecurity.com/files/170882/Zoho-ManageEng…exploitthird party advisoryvdb entry
- packetstormsecurity.com/files/170925/ManageEngine-A…exploitthird party advisoryvdb entry
- packetstormsecurity.com/files/170943/Zoho-ManageEng…exploitthird party advisoryvdb entry
- attackerkb.com/topics/gvs0Gv8BID/cve-2022-…exploitthird party advisory
- blog.viettelcybersecurity.com/saml-show-stopper/exploitthird party advisory
- github.com/apache/santuario-xml-securi…release notes
- github.com/horizon3ai/CVE-2022-47966third party advisory
- cisa.gov/news-events/cybersecurity-a…third party advisoryus government resource
- horizon3.ai/manageengine-cve-2022-47966…exploitthird party advisory
- manageengine.com/security/advisory/CVE/cve-2…patchvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource