LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-37415: Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 1, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 15, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-37415 to its Known Exploited Vulnerabilities catalog on Dec 1, 2021, with a federal patch deadline of Dec 15, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

CVE-2021-37415 is an authentication bypass in Zoho ManageEngine ServiceDesk Plus (SDP). Before build 11302, certain REST-API URLs could be reached without authentication. For IT and security teams this matters because ServiceDesk Plus often sits on internal networks with access to tickets, assets, and identity-related data; an unauthenticated path into those APIs can let an attacker interact with the product without valid credentials.

CISA lists the required action as applying updates per the vendor’s instructions. Confirm exact build numbers, fixed releases, and any environment-specific notes directly against the Zoho advisory.

How it works

The weakness is classified as CWE-306: Missing Authentication for Critical Function. In plain terms, a small set of REST-API endpoints that should require a logged-in session or valid token were reachable without that check.

An attacker who can reach the ServiceDesk Plus web interface (or a network path to it) can send requests to those unprotected URLs. Because no authentication is enforced on the affected paths, the requests may succeed and return or act on data the product would normally protect. Public detail on the exact request format and response content is limited; treat any deeper exploit mechanics as something to verify only from the vendor advisory or your own controlled testing, not from unverified sources.

Am I affected? How to find it in your systems

ServiceDesk Plus is commonly deployed as an on-premises or self-hosted IT service-management platform, often on Windows or Linux servers inside the corporate network or in a DMZ for remote technician access. It may also appear in virtual appliances or cloud-adjacent management setups.

How to remediate

Patch first. Apply the vendor update that brings ServiceDesk Plus to a fixed build (the CISA summary references the threshold of 11302; obtain the precise package and installation steps from Zoho’s advisory and release notes). Follow the vendor’s recommended backup and upgrade sequence so you do not lose configuration or ticket data.

After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps lower risk but do not replace the vendor patch. Schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited authentication-bypass flaws can lead to unauthorized access and, in some environments, broader compromise. Public reporting for this CVE does not document ransomware use, but that does not rule out other malicious activity. If logs or other evidence suggest the vulnerable APIs were reached while the instance was unpatched, treat the event as a potential incident: preserve logs, review ticket and asset data for unauthorized changes, and follow your incident-response process. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data to see whether related credentials have appeared in prior dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZoho · ManageEngine ServiceDesk Plus (SDP)
WeaknessCWE-306
Added to CISA KEVDec 1, 2021
Federal patch deadlineDec 15, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities