boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-47966CRITICAL
n/a n/a — Zoho ManageEngine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9975   100.0   YES
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Dec 26  Reserved by mitre
  Jan 23  Added to CISA KEV, remediation due 2023-02-13
  Jan 23  Published (CNA: mitre)
  Jul 31  EXPLOIT PUBLISHED — CVE-2022-47966. Public exploit reference added.
CWE-20 · CNA: mitre · CVSS v3.1 · 11 references · NVD status: Analyzed · KEV due February 13, 2023

Description

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
December 26, 2022ReservedReserved by mitre
January 23, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-02-13
January 23, 2023PublishedPublished (CNA: mitre)
July 31, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2022-47966. Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
n/an/an/a

Weaknesses

CWE-20

References (11)

Related

Authoritative record: CVE-2022-47966 at cve.org

Weaknesses: CWE-20

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-47966 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.