Executive brief
Zoho ManageEngine ServiceDesk Plus is vulnerable to an authentication bypass due to missing authentication for critical REST-API URLs. This allows unauthenticated remote attackers to access sensitive functions and data.
Affected products
- Zoho ManageEngine ServiceDesk Plus before 11302
Timeline
- 2021-12-01: disclosed
- 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-01: advisory: NVD publication date