CVE-2021-37415—Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
PUBLISHEDvulnerability record
2021-12-01 · last modified June 21, 2025
Metadata
Vulnerability Name
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
Description
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.