VendorsZoho Corpmanageengine_servicedesk_plus11.2
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 11.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Published 2021-09-01 · Analyzed
9.8KEVEPSS 0.998
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Published 2021-11-29 · Analyzed
9.8KEVEPSS 0.933
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Published 2021-12-23 · Modified
9.8EPSS 0.032
CVE-2021-20081
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
Published 2021-06-10 · Modified
9.0EPSS 0.524