THREATOPS
THREAT OPSThreat News › [NVD] CVE-2022-47966 (CRITICAL 9.8) — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsib

[NVD] CVE-2022-47966 (CRITICAL 9.8) — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsib

lownvdPublished 2023-01-18

CVE-2022-47966 CVSS: 9.8 CRITICAL Published: 2023-01-18T18:15:10.570

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the Manag

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-47966