CVE-2022-47966 | Zoho ManageEngine Access Manager Plus Apache xmlsec Remote Code Execution (Advisory 170882)
A vulnerability, which was classified as problematic, was found in Zoho ManageEngine Access Manager Plus, Active Directory 360, ADAudit Plus, ADManager Plus, ADSelfService Plus, Analytics Plus, Application Control Plus, Asset Explorer, Browser Security Plus, Device Control Plus, Endpoint Central, Endpoint Central MSP, Endpoint DLP, Key Manager Plus, OS Deployer, PAM 360, Password Manager Pro, Patch Manager Plus, Remote Access Plus, Remote Monitoring and Management, ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and Vulnerability Manager Plus. Affected by this issue is some unknown functionality of the component Apache xmlsec. The manipulation results in Remote Code Execution.
This vulnerability is cataloged as CVE-2022-47966. The attack may be launched remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.