Wiele produktów Zoho ManageEngine on-premise jest podatnych na zdalne wykonanie kodu (RCE) z powodu użycia przestarzałej wersji biblioteki Apache Santuario xmlsec (XML Security for Java) 1.4.1. Podatność jest krytyczna (CVSS 9.8), nie wymaga uwierzytelnienia ani interakcji użytkownika i jest aktywnie wykorzystywana przez atakujących.
▸ Pokaż oryginał (EN)
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Biblioteka Apache Santuario xmlsec w wersji 1.4.1 domyślnie udostępnia funkcje transformacji XSLT, które w założeniu projektowym wymagają od aplikacji nadrzędnej samodzielnego zapewnienia odpowiednich zabezpieczeń. Produkty ManageEngine nie implementowały wymaganych mechanizmów ochronnych, przez co atakujący może dostarczyć spreparowany dokument SAML zawierający złośliwy kod XSLT. Warunkiem koniecznym jest to, aby w produkcie kiedykolwiek skonfigurowano SAML SSO (dla niektórych produktów wymagane jest, aby SAML SSO było aktualnie aktywne). Wykonanie żądania z odpowiednio spreparowanym payloadem prowadzi do uruchomienia dowolnego kodu po stronie serwera bez żadnego uwierzytelnienia.
Nieuwierzytelniony atakujący zdalnie może wykonać dowolny kod na serwerze (RCE), co potencjalnie prowadzi do pełnego przejęcia systemu, kradzieży danych, instalacji malware lub lateral movement w sieci organizacji.
Należy natychmiast zaktualizować wszystkie produkty Zoho ManageEngine do wersji wskazanych powyżej jako bezpieczne (lub nowszych). Jeśli natychmiastowa aktualizacja nie jest możliwa, należy tymczasowo wyłączyć konfigurację SAML SSO we wszystkich dotkniętych produktach, co eliminuje wektor ataku. Patche należy pobrać zgodnie z oficjalnymi referencjami producenta.
Wiele produktów Zoho ManageEngine on-premise: Access Manager Plus przed 4308, Active Directory 360 przed 4310, ADAudit Plus przed 7081, ADManager Plus przed 7162, ADSelfService Plus przed 6211, Analytics Plus przed 5150, Application Control Plus przed 10.1.2220.18, Asset Explorer przed 6983, Browser Security Plus przed 11.1.2238.6, Device Control Plus przed 10.1.2220.18, Endpoint Central przed 10.1.2228.11, Endpoint Central MSP przed 10.1.2228.11, Endpoint DLP przed 10.1.2137.6, Key Manager Plus przed 6401, OS Deployer przed 1.1.2243.1, PAM 360 przed 5713, Password Manager Pro przed 12124, Patch Manager Plus przed 10.1.2220.18, Remote Access Plus przed 10.1.2228.11, Remote Monitoring and Management (RMM) przed 10.1.41, ServiceDesk Plus przed 14004, ServiceDesk Plus MSP przed 13001, SupportCenter Plus przed 11026, Vulnerability Manager Plus przed 10.1.2220.18.
Podatność dotyczy wyłącznie instancji, w których kiedykolwiek skonfigurowano SAML SSO (dla części produktów wymagane jest aktywne SAML SSO). Publicznie dostępne są gotowe exploity dla ServiceDesk Plus 14003, ADSelfService Plus oraz Endpoint Central MSP 10.1.2228.10. Podatność została potwierdzona przez CISA jako aktywnie eksploatowana i umieszczona w katalogu KEV.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Access Manager Plus
APPZohocorp4.3< 4.3Zohocorp Manageengine Ad360
APPZohocorp4.3< 4.3Zohocorp Manageengine Adaudit Plus
APPZohocorp7.0< 7.0Zohocorp Manageengine Admanager Plus
APPZohocorp7.1< 7.1Zohocorp Manageengine Adselfservice Plus
APPZohocorp6.2< 6.2Zohocorp Manageengine Analytics Plus
APPZohocorp5.1< 5.1Zohocorp Manageengine Application Control Plus
APPZohocorp< 10.1.2220.18Zohocorp Manageengine Assetexplorer
APPZohocorp6.9< 6.9Zohocorp Manageengine Browser Security Plus
APPZohocorp< 11.1.2238.6Zohocorp Manageengine Device Control Plus
APPZohocorp< 10.1.2220.18Zohocorp Manageengine Endpoint Dlp Plus
APPZohocorp< 10.1.2137.6Zohocorp Manageengine Key Manager Plus
APPZohocorp6.4< 6.4Zohocorp Manageengine Os Deployer
APPZohocorp< 1.1.2243.1Zohocorp Manageengine Pam360
APPZohocorp5.7< 5.7Zohocorp Manageengine Password Manager Pro
APPZohocorp12.1< 12.1Zohocorp Manageengine Patch Manager Plus
APPZohocorp< 10.1.2220.18Zohocorp Manageengine Remote Access Plus
APPZohocorp< 10.1.2228.11Zohocorp Manageengine Remote Monitoring And Management Central
APPZohocorp< 10.1.41Zohocorp Manageengine Servicedesk Plus
APPZohocorp14.0< 14.0Zohocorp Manageengine Servicedesk Plus Msp
APPZohocorp13.0< 13.0Zohocorp Manageengine Supportcenter Plus
APPZohocorp11.0Zohocorp Manageengine Vulnerability Manager Plus
APPZohocorp< 10.1.2220.18
CISA KEV — szczegółyi
- Dostawcai
- Zoho ↗
- Produkti
- ManageEngine
- Data dodania do KEVi
- 23 stycznia 2023
- Termin remediation (USA)i
- 13 lutego 2023(po terminie)
- Ransomwarei
- Aktywne kampanie ransomware używają tej podatności
Zastosuj aktualizacje zgodnie z instrukcjami producenta.
▸ Pokaż oryginał (EN)
Apply updates per vendor instructions.
Wiele produktów Zoho ManageEngine zawiera lukę umożliwiającą nieuwierzytelniony zdalny przejęcie kontroli (RCE) z powodu użycia przestarzałej zależności od strony trzeciej, Apache Santuario.
▸ Pokaż oryginał (EN)
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
Powiązane podatności
Zdalne wykonanie kodu w Zoho ManageEngine Password Manager Pro i PAM360
Nieuwierzytelniony RCE w Zoho ManageEngine ServiceDesk Plus
Zoho ManageEngine ADSelfService Plus — Auth Bypass i RCE przez REST API
Pominięcie uwierzytelnienia w REST API Zoho ManageEngine ServiceDesk Plus
Authentication Bypass w Zohocorp ManageEngine ADSelfService Plus