CVE-2021-37415
zohocorp manageengine servicedesk plus
Published 1 Sept 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 1 Dec 2021, with a remediation deadline of 15 Dec 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
References
- www.manageengine.com/ · Product
- www.manageengine.com/products/service-desk/on-premises/readme.html#11302 · Release Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-37415 · US Government Resource