← Back

CVE-2021-37415

Published: Sep 1, 2021Modified: Oct 31, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Affected (65)

1 product
Manageengine Servicedesk Plus
Configuration A
65 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Version 11.0 11005
Version 11.0 11006
Version 11.0 11007
Version 11.0 11008
Version 11.0 11009
Version 11.0 11010
Version 11.0 11011
Version 11.1
Version 11.1 11100
Version 11.1 11101
Version 11.1 11102
Version 11.1 11103
Version 11.1 11104
Version 11.1 11105
Version 11.1 11106
Version 11.1 11107
Version 11.1 11108
Version 11.1 11109
Version 11.1 11110
Version 11.1 11111
Version 11.1 11112
Version 11.1 11113
Version 11.1 11114
Version 11.1 11115
Version 11.1 11116
Version 11.1 11117
Version 11.1 11118
Version 11.1 11119
Version 11.1 11120
Version 11.1 11121
Version 11.1 11122
Version 11.1 11123
Version 11.1 11124
Version 11.1 11125
Version 11.1 11126
Version 11.1 11127
Version 11.1 11128
Version 11.1 11129
Version 11.1 11130
Version 11.1 11131
Version 11.1 11132
Version 11.1 11133
Version 11.1 11134
Version 11.1 11135
Version 11.1 11136
Version 11.1 11137
Version 11.1 11138
Version 11.1 11139
Version 11.1 11140
Version 11.1 11141
Version 11.1 11142
Version 11.1 11143
Version 11.1 11144
Version 11.2
Version 11.2 11200
Version 11.2 11201
Version 11.2 11202
Version 11.2 11203
Version 11.2 11204
Version 11.2 11205
Version 11.2 11206
Version 11.2 11207
Version 11.3
Version 11.3 11300
Version 11.3 11301

References (5)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.