Disclosure summary
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2021-12-01T00:00:00-05:00
MODIFIED 2021-12-01T00:00:00-05:00
INGESTED 2026-10-06T11:42:59-04:00