EXPOSURES › CVE-2021-37415
CVE-2021-37415
HIGH ⌖ ON CISA KEV · EXPLOITEDAn authentication bypass in Zoho ManageEngine ServiceDesk Plus allowed unauthenticated access to REST-API URLs, enabling attackers to bypass login and potentially access sensitive IT service data.
The vulnerability allowed attackers to access REST-API endpoints without authentication, exposing sensitive IT service management data and potentially enabling further attacks. DIB organizations using this product must patch immediately and monitor for unauthorized API access. This is a known, unpatched vulnerability that was actively exploited in the wild.
Shame score — A known authentication bypass vulnerability remained unpatched and was actively exploited in the wild, allowing unauthenticated access to sensitive IT service data.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication