Skip to main content
dmaciejak
Staff
Staff
July 20, 2023

Outbreak Alert: Zoho ManageEngine RCE Vulnerability

  • July 20, 2023
  • 0 replies
  • 692 views
Description

This article describes multiple Zoho ManageEngine on-premise products vulnerability detection with FortiDevSec.

 

Products such as ServiceDesk Plus, Password Manager Pro and ADSelfService Plus have been found to be affected by CVE-2022-47966.

Successful exploitation of an outdated third party dependency Apache Santuario could lead to remote code execution.

Scope FortiDevSec SCA scanner updated in version 23.2.a
Solution

Detection against these vulnerabilities is empowered by the FortiDevSec Software Composition Analysis (SCA) scanner.

 

This technology enables FortiDevSec to assess with a high level of confidence if the application codebase is vulnerable to a specific vulnerability by identifying open-source software dependencies.

 

The SCA scanner is enabled by default. Once the scan is performed on an application, the result appears under the Software Composition Analysis tab.

 

A step-by-step guide on how to scan an application is available in the user guide.

 

For more details regarding mitigating the vulnerability by utilizing Fortinet products, refer to Zoho ManageEngine RCE Vulnerability - FortiGuard Outbreak Alerts.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!