Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Servicedesk Plus
APPZohocorp11.011.111.211.3
CISA KEV — detailsi
- Vendori
- Zoho ↗
- Producti
- ManageEngine ServiceDesk Plus (SDP)
- Added to KEVi
- December 1, 2021
- Remediation deadline (US Federal)i
- December 15, 2021(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 15 grudnia 2021
Tags
Auth Bypass
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2021-44077CRITICAL9.8⚠ KEVPL ✓same product
Nieuwierzytelniony RCE w Zoho ManageEngine ServiceDesk Plus
CVE-2021-44526CRITICAL9.8PL ✓same product
Auth Bypass w Zoho ManageEngine ServiceDesk Plus (przed wersją 12003)
CVE-2019-8395CRITICAL9.8PL ✓same product
IDOR i Path Traversal w Zoho ManageEngine ServiceDesk Plus
CVE-2024-38869HIGH8.3same product
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office depl...