CVE-2022-47966

Exp

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

Published: 2023-01-18 Last update: 2025-10-31 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-47966 is rated Critical Active Threat (99.5/100): CVSS Critical severity, with high exploitation likelihood (EPSS 94.43%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2023-01-23) affecting Zoho / ManageEngine. a weakness (CWE-20) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2022-47966

Name: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability · CISA KEV detail

Exploit added: 2023-01-23

Action due: 2023-02-13

Required action: Apply updates per vendor instructions.

Public exploit references (Exploit-DB) for CVE-2022-47966

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2022-47966

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-21 94.08% 94.43% +0.35%
2 2025-11-18 94.43% 94.08% -0.35%
3 2025-03-30 94.43%

Full EPSS history (29 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-47966

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2022-47966

OS Trackers for CVE-2022-47966

vendor priority summary link
redhat high https://access.redhat.com/security/cve/CVE-2022-47966

Affected software / configurations for CVE-2022-47966

Vendor Product Version Raw CPE
zohocorp manageengine_access_manager_plus < 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4300:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4301:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4302:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4303:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4304:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4305:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4306:*:*:*:*:*:*
zohocorp manageengine_access_manager_plus 4.3 cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4307:*:*:*:*:*:*
zohocorp manageengine_ad360 < 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:*:*:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4300:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4302:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4303:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4304:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4305:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4306:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4308:*:*:*:*:*:*
zohocorp manageengine_ad360 4.3 cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4309:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus < 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7000:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7002:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7003:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7004:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7005:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7006:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7007:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7008:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7050:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7051:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7052:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7053:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7054:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7055:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7060:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7062:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7063:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7065:*:*:*:*:*:*
zohocorp manageengine_adaudit_plus 7.0 cpe:2.3:a:zohocorp:manageengine_adaudit_plus:7.0:7080:*:*:*:*:*:*
zohocorp manageengine_admanager_plus < 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7100:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7101:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7102:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7110:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7111:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7112:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7113:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7114:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7115:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7116:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7117:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7118:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7120:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7121:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7122:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7123:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7124:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7125:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7126:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7130:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7131:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7140:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7141:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7150:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7151:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7160:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7161:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus < 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6200:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6201:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6202:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6203:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6204:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6205:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6206:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6207:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6208:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6209:*:*:*:*:*:*
zohocorp manageengine_adselfservice_plus 6.2 cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6210:*:*:*:*:*:*
zohocorp manageengine_analytics_plus < 5.1 cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:*
zohocorp manageengine_analytics_plus 5.1 cpe:2.3:a:zohocorp:manageengine_analytics_plus:5.1:5100:*:*:*:*:*:*

References for CVE-2022-47966

URL Tags
http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysis Exploit Third Party Advisory
https://blog.viettelcybersecurity.com/saml-show-stopper/ Exploit Third Party Advisory
https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6 Release Notes
https://github.com/horizon3ai/CVE-2022-47966 Third Party Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a Third Party Advisory US Government Resource
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/ Exploit Third Party Advisory
https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html Patch Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47966 US Government Resource
cvelogic Threat Intelligence