Executive brief
Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus are vulnerable to unauthenticated remote code execution due to missing authentication for critical functions. The flaw is related to /RestAPI URLs in a servlet and ImportTechnicians in the Struts configuration, allowing an attacker to execute arbitrary code.
Affected products
- Zoho ManageEngine ServiceDesk Plus before 11306
- Zoho ManageEngine ServiceDesk Plus MSP before 10530
- Zoho ManageEngine SupportCenter Plus before 11014
Timeline
- 2021-12-01: disclosed
- 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog