Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. Required action: Apply updates per vendor instructions.
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. Required action: Apply updates per vendor instructions.
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. Required action: Apply updates per vendor instructions.
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication Required action: Apply updates per vendor instructions.
CVE-2021-37415EPSS 99.9%ManageEngine ServiceDesk Plus (SDP)Zoho
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution Required action: Apply updates per vendor instructions.
CVE-2021-44077EPSS 93.5%ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusZoho
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. Required action: Apply updates per vendor instructions.
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. Required action: Apply updates per vendor instructions.