SOURCE FACT
Zoho · ManageEngine ServiceDesk Plus (SDP)
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-37415
View source evidence →