VendorsZoho Corpmanageengine_servicedesk_plus11.3
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 11.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Published 2021-09-01 · Analyzed
9.8KEVEPSS 0.998
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Published 2021-11-29 · Analyzed
9.8KEVEPSS 0.933
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Published 2021-12-23 · Modified
9.8EPSS 0.032
CVE-2021-46065
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
Published 2022-01-27 · Modified
4.8EPSS 0.917