QID 376146

Date Published: 2021-12-27

QID 376146: Zoho ManageEngine ServiceDesk Plus Authentication Bypass (SD-96823)

Zoho ManageEngine ServiceDesk Plus is a Help Desk and Asset Management Software. It offers an Integrated Package with Incident Management(Trouble Ticketing), Asset Tracking, Purchasing, Contract Management, Self-Service Portal, and Knowledge Base.
Zoho ManageEngine ServiceDesk Plus is vulnerable to authentication bypass. Affected Versions:
Zoho ManageEngine ServiceDesk Plus before 11302

A successful exploitation of this vulnerability allows authentication bypass to a few REST-API URLs without authentication.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Update to Zoho ManageEngine ServiceDesk Plus 11303 or later.

    CVEs related to QID 376146

    Software Advisories
    Advisory ID Software Component Link
    SD-96823 URL Logo www.manageengine.com/products/service-desk/on-premises/readme.html#11302