VendorsZoho Corpmanageengine_servicedesk_plus11.1
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 11.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Published 2021-09-01 · Analyzed
9.8KEVEPSS 0.998
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Published 2021-11-29 · Analyzed
9.8KEVEPSS 0.933
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Published 2021-12-23 · Modified
9.8EPSS 0.032
CVE-2020-35682
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
Published 2021-03-13 · Modified
8.8EPSS 0.072
CVE-2020-14048
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
Published 2020-06-12 · Modified
7.5EPSS 0.048
CVE-2020-13154
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
Published 2020-05-18 · Modified
6.5EPSS 0.031
CVE-2021-20080
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
Published 2021-04-09 · Modified
6.1EPSS 0.931