CRITICAL
CVE-2021-37415
CVSS
9.8
KEV
Description
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Summary dbcve.org
Zoho ManageEngine ServiceDesk Plus versions before 11302 contain an authentication bypass vulnerability in the REST API that allows certain API endpoints to be accessed without authentication. This critical flaw (CVSS 9.8) enables remote unauthenticated attackers to potentially access or manipulate sensitive service desk data and operations.
Mitigation
Upgrade ManageEngine ServiceDesk Plus to version 11302 or later to remediate the authentication bypass vulnerability in the REST API.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
99.83%
Probability of exploitation in next 30 days
100th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.