ID:8815 - Exploit for Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966

 
Main Vulnerability Database Exploits ID:8815 - Exploit for Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966

ID:8815 - Exploit for Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966

Published: February 8, 2023


Vulnerability identifier: #VU71210
Vulnerability risk: High
CVE-ID: CVE-2022-47966
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Apache Santuario XML Security for Java

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to unspecified error in the Apache Santuario, which affects Zoho ManageEngine products, when SAML SSO is enabled. A remote non-authenticated attacker can bypass authentication process and compromise the affected system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.