← Back

CVE-2021-44077

Published: Nov 29, 2021Modified: Oct 31, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Affected (73)

3 products
Manageengine Servicedesk Plus
Manageengine Servicedesk Plus Msp
Manageengine Supportcenter Plus
Configuration A
73 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 11.1
Version 11.1 11138
Version 11.1 11139
Version 11.1 11140
Version 11.1 11141
Version 11.1 11142
Version 11.1 11143
Version 11.1 11144
Version 11.1 11145
Version 11.2 11200
Version 11.2 11201
Version 11.2 11202
Version 11.2 11203
Version 11.2 11204
Version 11.2 11205
Version 11.2 11206
Version 11.2 11207
Version 11.2 11208
Version 11.2 11209
Version 11.2 11210
Version 11.2 11211
Version 11.3 11300
Version 11.3 11301
Version 11.3 11302
Version 11.3 11303
Version 11.3 11304
Version 11.3 11305
Zohocorp
Before 10.5
Version 10.5 10500
Version 10.5 10501
Version 10.5 10502
Version 10.5 10503
Version 10.5 10504
Version 10.5 10505
Version 10.5 10506
Version 10.5 10507
Version 10.5 10508
Version 10.5 10509
Version 10.5 10510
Version 10.5 10511
Version 10.5 10512
Version 10.5 10513
Version 10.5 10514
Version 10.5 10515
Version 10.5 10516
Version 10.5 10517
Version 10.5 10518
Version 10.5 10519
Version 10.5 10520
Version 10.5 10521
Version 10.5 10522
Version 10.5 10523
Version 10.5 10524
Version 10.5 10525
Version 10.5 10526
Version 10.5 10527
Version 10.5 10528
Version 10.5 10529
Zohocorp
Before 11.0
Version 11.0 11000
Version 11.0 11001
Version 11.0 11002
Version 11.0 11003
Version 11.0 11004
Version 11.0 11005
Version 11.0 11006
Version 11.0 11007
Version 11.0 11008
Version 11.0 11009
Version 11.0 11010
Version 11.0 11011
Version 11.0 11012
Version 11.0 11013

References (11)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.