Salesforce is following our vulnerability management process in patching Salesforce services to address the security issues referenced in these vulnerabilities. For more details specific to individual services, see below.
|
Product |
Status |
|
Sales Cloud |
Sales Cloud is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Service Cloud |
Service Cloud has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Dataloader |
Dataloader is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Experience (Community) Cloud |
Experience Cloud has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
B2B Commerce Cloud |
B2B Commerce Cloud is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
B2C Commerce Cloud |
B2C Commerce Cloud has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Marketing Cloud |
Marketing Cloud is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Marketing Cloud Account Engagement (Pardot) |
Marketing Cloud Account Engagement is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Evergage (Interaction Studio) |
Evergage is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Datorama |
Datorama is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Data.com |
Data.com is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Heroku |
Heroku is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
MuleSoft (Cloud) |
MuleSoft (Cloud) is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
MuleSoft (On-Premise) |
MuleSoft (On-Premise) is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
ClickSoftware (As-a-Service) |
ClickSoftware (As-a-Service) has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
ClickSoftware (On-Premise) |
ClickSoftware (On-Premise) has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Tableau (Online) |
Tableau Online is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Tableau (On-Premise) |
Tableau (On-Premise) is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Slack |
Slack is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Quip |
Quip is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Analytics Cloud |
Analytics Cloud is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
Philanthropy Cloud |
Philanthropy Cloud has been patched to address the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
|
AppExchange |
AppExchange is not affected by the issues currently identified in CVE-2022-22963 and CVE 2022-22965. |
We are actively working with our third-party vendors and partners to ensure they have mitigations in place and are updating their software or services to remediate the issues referenced in CVE-2022-22963 and CVE 2022-22965. As these issues continue to evolve, we will implement additional remediation actions as appropriate.
As part of our continuous detection and monitoring systems, we have implemented detection and monitoring to alert for any potential exploitation attempts. If Salesforce becomes aware of unauthorized access to Customer Data, we will notify impacted customers without undue delay.
Updates will be posted to status.salesforce.com as additional information becomes available.
000390926

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.