📦 Manageengine Servicedesk Plus

by Zohocorp

🔍 What is Manageengine Servicedesk Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-44526

CRITICAL CVSS 9.8 Dec 23, 2021

CVE-2021-44526 is an authentication bypass vulnerability in Zoho ManageEngine ServiceDesk Plus that allows attackers to gain unauthorized administrative access. Organizations using affected versions w...

CVE-2021-44077

CRITICAL CVSS 9.8 Nov 29, 2021

CVE-2021-44077 is an unauthenticated remote code execution vulnerability in Zoho ManageEngine products. Attackers can exploit this via specific REST API endpoints to execute arbitrary code without cre...

CVE-2021-37415

CRITICAL CVSS 9.8 Sep 1, 2021

CVE-2021-37415 is an authentication bypass vulnerability in Zoho ManageEngine ServiceDesk Plus where certain REST-API URLs don't require authentication. This allows attackers to access sensitive funct...

CVE-2024-38869

HIGH CVSS 8.3 Aug 23, 2024

This vulnerability allows attackers to bypass authorization controls in ManageEngine Endpoint Central's remote office deployment configurations. Attackers could potentially modify deployment settings ...

CVE-2022-35403

HIGH CVSS 7.5 Jul 12, 2022

This vulnerability allows unauthenticated attackers to read local files on Zoho ManageEngine servers via specially crafted ticket-creation emails. It affects ServiceDesk Plus, ServiceDesk Plus MSP, Su...

CVE-2021-31160

HIGH CVSS 7.5 Jun 29, 2021

This vulnerability in Zoho ManageEngine ServiceDesk Plus MSP allows attackers to access internal data without proper authentication. It affects organizations using ServiceDesk Plus MSP for IT service ...

CVE-2021-20081

HIGH CVSS 7.2 Jun 10, 2021

This vulnerability allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges on ManageEngine ServiceDesk Plus servers. Attackers can gain complete control of affected ...

CVE-2020-35682

HIGH CVSS 8.8 Mar 13, 2021

This vulnerability allows attackers to bypass authentication during SAML login in Zoho ManageEngine ServiceDesk Plus. Affected organizations using SAML authentication with versions before 11134 are at...