CRITICAL

CVE-2021-37415

Zohocorp Manageengine Servicedesk Plus 2021-09-01 CVSS v3.1
CVSS
9.8
KEV

Description

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Summary dbcve.org

Zoho ManageEngine ServiceDesk Plus versions before 11302 contain an authentication bypass vulnerability in the REST API that allows certain API endpoints to be accessed without authentication. This critical flaw (CVSS 9.8) enables remote unauthenticated attackers to potentially access or manipulate sensitive service desk data and operations.

Mitigation

Upgrade ManageEngine ServiceDesk Plus to version 11302 or later to remediate the authentication bypass vulnerability in the REST API.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

99.83%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE