VendorsZoho Corpmanageengine_servicedesk_plus_msp10.5
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus MSP 10.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Published 2021-11-29 · Analyzed
9.8KEVEPSS 0.933
CVE-2021-44675
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
Published 2021-12-20 · Modified
9.8EPSS 0.065
CVE-2021-31531
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
Published 2021-06-29 · Modified
9.8EPSS 0.024
CVE-2021-31160
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
Published 2021-06-29 · Modified
7.5EPSS 0.035
CVE-2021-31530
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
Published 2021-06-29 · Modified
7.5EPSS 0.028
CVE-2021-31159
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
Published 2021-06-16 · Modified
5.31 PoCEPSS 0.178