CVE-2021-44077
Description
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Summary dbcve.org
Unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus via the /RestAPI servlet path combined with the ImportTechnicians action in the Apache Struts configuration. A remote attacker without credentials can send crafted requests to this endpoint to achieve code execution on the underlying host.
Mitigation
Upgrade affected ManageEngine installations to the fixed versions: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later. Apply the vendor patch promptly given the critical severity and unauthenticated attack vector, and review server logs for prior exploitation of /RestAPI and ImportTechnicians requests.