Lucene search

K
cveMitreCVE-2021-44077
HistoryNov 29, 2021 - 4:15 a.m.

CVE-2021-44077

2021-11-2904:15:06
CWE-306
mitre
web.nvd.nist.gov
995
In Wild
35
cve-2021-44077
zoho
manageengine
servicedesk
remote code execution
security vulnerability
nvd
unauthenticated access

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.974

Percentile

99.9%

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Affected configurations

Nvd
Node
zohocorpmanageengine_servicedesk_plusMatch11.111138
OR
zohocorpmanageengine_servicedesk_plusMatch11.111139
OR
zohocorpmanageengine_servicedesk_plusMatch11.111140
OR
zohocorpmanageengine_servicedesk_plusMatch11.111141
OR
zohocorpmanageengine_servicedesk_plusMatch11.111142
OR
zohocorpmanageengine_servicedesk_plusMatch11.111143
OR
zohocorpmanageengine_servicedesk_plusMatch11.111144
OR
zohocorpmanageengine_servicedesk_plusMatch11.111145
OR
zohocorpmanageengine_servicedesk_plusMatch11.211200
OR
zohocorpmanageengine_servicedesk_plusMatch11.211201
OR
zohocorpmanageengine_servicedesk_plusMatch11.211202
OR
zohocorpmanageengine_servicedesk_plusMatch11.211203
OR
zohocorpmanageengine_servicedesk_plusMatch11.211204
OR
zohocorpmanageengine_servicedesk_plusMatch11.211205
OR
zohocorpmanageengine_servicedesk_plusMatch11.211206
OR
zohocorpmanageengine_servicedesk_plusMatch11.211207
OR
zohocorpmanageengine_servicedesk_plusMatch11.211208
OR
zohocorpmanageengine_servicedesk_plusMatch11.211209
OR
zohocorpmanageengine_servicedesk_plusMatch11.211210
OR
zohocorpmanageengine_servicedesk_plusMatch11.211211
OR
zohocorpmanageengine_servicedesk_plusMatch11.311300
OR
zohocorpmanageengine_servicedesk_plusMatch11.311301
OR
zohocorpmanageengine_servicedesk_plusMatch11.311302
OR
zohocorpmanageengine_servicedesk_plusMatch11.311303
OR
zohocorpmanageengine_servicedesk_plusMatch11.311304
OR
zohocorpmanageengine_servicedesk_plusMatch11.311305
OR
zohocorpmanageengine_servicedesk_plus_mspRange10.5
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510500
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510501
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510502
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510503
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510504
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510505
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510506
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510507
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510508
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510509
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510510
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510511
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510512
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510513
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510514
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510515
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510516
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510517
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510518
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510519
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510520
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510521
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510522
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510523
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510524
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510525
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510526
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510527
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510528
OR
zohocorpmanageengine_servicedesk_plus_mspMatch10.510529
OR
zohocorpmanageengine_supportcenter_plusRange11.0
OR
zohocorpmanageengine_supportcenter_plusMatch11.011000
OR
zohocorpmanageengine_supportcenter_plusMatch11.011001
OR
zohocorpmanageengine_supportcenter_plusMatch11.011002
OR
zohocorpmanageengine_supportcenter_plusMatch11.011003
OR
zohocorpmanageengine_supportcenter_plusMatch11.011004
OR
zohocorpmanageengine_supportcenter_plusMatch11.011005
OR
zohocorpmanageengine_supportcenter_plusMatch11.011006
OR
zohocorpmanageengine_supportcenter_plusMatch11.011007
OR
zohocorpmanageengine_supportcenter_plusMatch11.011008
OR
zohocorpmanageengine_supportcenter_plusMatch11.011009
OR
zohocorpmanageengine_supportcenter_plusMatch11.011010
OR
zohocorpmanageengine_supportcenter_plusMatch11.011011
OR
zohocorpmanageengine_supportcenter_plusMatch11.011012
OR
zohocorpmanageengine_supportcenter_plusMatch11.011013
VendorProductVersionCPE
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11138:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11139:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11140:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11141:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11142:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11143:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11144:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.1cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11145:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.2cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11200:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus11.2cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11201:*:*:*:*:*:*
Rows per page:
1-10 of 721

Social References

More

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.974

Percentile

99.9%