Junglewise Threat Intelligence

CVE-2021-37415: Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

CVE-2021-37415 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-12-01

Vendors: Zoho.

Executive brief

Zoho ManageEngine ServiceDesk Plus is vulnerable to an authentication bypass due to missing authentication for critical REST-API URLs. This allows unauthenticated remote attackers to access sensitive functions and data.

Affected products

  • Zoho ManageEngine ServiceDesk Plus before 11302

Timeline

  • 2021-12-01: disclosed
  • 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-12-01: advisory: NVD publication date

Related threats