CVE-2022-40771
Description
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zoho ManageEngine ServiceDesk Plus and related products are vulnerable to XXE injection via Analytics Plus integration, allowing admin-level attackers to read local files.
Vulnerability
Zoho ManageEngine ServiceDesk Plus (versions 14000 and below), ServiceDesk Plus MSP (13000 and below), SupportCenter Plus (11025 and below), and AssetExplorer (6980 and below) are vulnerable to an XML External Entity (XXE) injection vulnerability when integrating with Analytics Plus. The vulnerability arises because the product does not properly restrict XML parsing when processing responses from an Analytics Plus server, allowing an attacker to inject malicious XML entities [2].
Exploitation
Exploitation requires an attacker to have admin role access to the affected product. The attacker can set up a malicious Analytics Plus server and configure the product to integrate with it. When the product processes the XML response from the malicious server, an external entity reference is resolved, enabling the attacker to read arbitrary files from the server filesystem [2].
Impact
Successful exploitation allows an attacker with admin privileges to retrieve local files from the server running the affected product. This leads to information disclosure of sensitive data such as configuration files, credentials, or other confidential information stored on the server [2].
Mitigation
Zoho has released fixed versions: ServiceDesk Plus 14001 (October 14, 2022), ServiceDesk Plus MSP 13001 (October 27, 2022), SupportCenter Plus 11026 (October 28, 2022), and AssetExplorer 6981 (October 13, 2022). Users should upgrade to the latest build as per the upgrade pack instructions provided in the advisory [2]. No workaround is documented.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine ServiceDesk Plusdescription
- Range: <=13010
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.