Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_servicedesk_plus | Zohocorp | 11.1-11138 (including) | 11.1-11138 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11139 (including) | 11.1-11139 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11140 (including) | 11.1-11140 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11141 (including) | 11.1-11141 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11142 (including) | 11.1-11142 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11143 (including) | 11.1-11143 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11144 (including) | 11.1-11144 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11145 (including) | 11.1-11145 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11200 (including) | 11.2-11200 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11201 (including) | 11.2-11201 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11202 (including) | 11.2-11202 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11203 (including) | 11.2-11203 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11204 (including) | 11.2-11204 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11205 (including) | 11.2-11205 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11206 (including) | 11.2-11206 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11207 (including) | 11.2-11207 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11208 (including) | 11.2-11208 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11209 (including) | 11.2-11209 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11210 (including) | 11.2-11210 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-11211 (including) | 11.2-11211 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11300 (including) | 11.3-11300 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11301 (including) | 11.3-11301 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11302 (including) | 11.3-11302 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11303 (including) | 11.3-11303 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11304 (including) | 11.3-11304 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.3-11305 (including) | 11.3-11305 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | * | 10.5 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10500 (including) | 10.5-10500 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10501 (including) | 10.5-10501 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10502 (including) | 10.5-10502 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10503 (including) | 10.5-10503 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10504 (including) | 10.5-10504 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10505 (including) | 10.5-10505 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10506 (including) | 10.5-10506 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10507 (including) | 10.5-10507 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10508 (including) | 10.5-10508 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10509 (including) | 10.5-10509 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10510 (including) | 10.5-10510 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10511 (including) | 10.5-10511 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10512 (including) | 10.5-10512 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10513 (including) | 10.5-10513 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10514 (including) | 10.5-10514 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10515 (including) | 10.5-10515 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10516 (including) | 10.5-10516 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10517 (including) | 10.5-10517 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10518 (including) | 10.5-10518 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10519 (including) | 10.5-10519 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10520 (including) | 10.5-10520 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10521 (including) | 10.5-10521 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10522 (including) | 10.5-10522 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10523 (including) | 10.5-10523 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10524 (including) | 10.5-10524 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10525 (including) | 10.5-10525 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10526 (including) | 10.5-10526 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10527 (including) | 10.5-10527 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10528 (including) | 10.5-10528 (including) |
Manageengine_servicedesk_plus_msp | Zohocorp | 10.5-10529 (including) | 10.5-10529 (including) |
Manageengine_supportcenter_plus | Zohocorp | * | 11.0 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11000 (including) | 11.0-11000 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11001 (including) | 11.0-11001 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11002 (including) | 11.0-11002 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11003 (including) | 11.0-11003 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11004 (including) | 11.0-11004 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11005 (including) | 11.0-11005 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11006 (including) | 11.0-11006 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11007 (including) | 11.0-11007 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11008 (including) | 11.0-11008 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11009 (including) | 11.0-11009 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11010 (including) | 11.0-11010 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11011 (including) | 11.0-11011 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11012 (including) | 11.0-11012 (including) |
Manageengine_supportcenter_plus | Zohocorp | 11.0-11013 (including) | 11.0-11013 (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.