PT-2021-6071 · Zoho+1 · Zoho Manageengine Servicedesk Plus+2

Published

2021-11-28

·

Updated

2025-10-31

·

CVE-2021-44077

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus versions prior to 11306 Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10530 Zoho ManageEngine SupportCenter Plus versions prior to 11014
Description The issue is related to unauthenticated remote code execution and is associated with the lack of an authentication procedure. This can allow a remote attacker to execute arbitrary code. The vulnerability is related to /RestAPI URLs in a servlet and ImportTechnicians in the Struts configuration. It has been observed that cybercriminals are using this vulnerability, and 5.7% of all vulnerable software versions are used in Russia.
Recommendations For Zoho ManageEngine ServiceDesk Plus versions prior to 11306, update to version 11306 or later. For Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10530, update to version 10530 or later. For Zoho ManageEngine SupportCenter Plus versions prior to 11014, update to version 11014 or later. As a temporary workaround, consider restricting access to the /RestAPI URLs in the affected servlet and disabling the ImportTechnicians function in the Struts configuration until a patch is applied.

Exploit

Fix

RCE

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-00677
CVE-2021-44077

Affected Products

Struts
Zoho Manageengine Servicedesk Plus
Zoho Manageengine Supportcenter Plus