CVE-2021-37415 — Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

CVE-2021-37415

Zoho ManageEngine ServiceDesk Plus — Unauthenticated REST API Access Before Build 11302 Allowing Account Takeover and Credential Exposure

What is Zoho ManageEngine ServiceDesk Plus?

Zoho ManageEngine ServiceDesk Plus (SDP) is an enterprise IT helpdesk and IT service management (ITSM) platform used by thousands of organizations to manage support tickets, asset inventory, change management, and IT service delivery. ServiceDesk Plus stores sensitive information including employee contact data, IT asset configurations, and credentials submitted via support tickets. It integrates with Active Directory and often runs in a privileged network position with access to IT management systems.

Overview

CVE-2021-37415 is an authentication bypass vulnerability (CWE-306 — missing authentication for critical function) in Zoho ManageEngine ServiceDesk Plus before build 11302. Certain REST API URLs are accessible without authentication due to missing or incorrectly configured authentication checks. An unauthenticated attacker can access these endpoints to retrieve sensitive data, create or modify records, or in combination with other weaknesses, achieve account takeover. This is a distinct and earlier vulnerability from CVE-2021-44077 (the later unauthenticated file upload RCE).

Affected Versions

Product Vulnerable Fixed
ServiceDesk Plus < Build 11302 Build 11302

Technical Details

ServiceDesk Plus uses a Java Servlet filter to enforce authentication on web requests. The filter's URL pattern matching fails to cover certain REST API endpoints:

  • Root cause: Missing authentication (CWE-306) — specific REST API URL patterns are not matched by the authentication enforcement filter, making them accessible without authentication
  • Accessible data: Unauthenticated access to REST API endpoints can expose ticket data, user account information, asset inventory, and ServiceDesk configuration
  • Account operations: Some unauthenticated REST API endpoints may allow modification of account states or retrieval of sensitive data that enables further exploitation
  • Relationship to CVE-2021-44077: CVE-2021-37415 (August 2021) is an earlier auth bypass; CVE-2021-44077 (November 2021) is a more severe unauthenticated file upload RCE — organizations may have patched the file upload RCE while remaining unaware of this earlier auth bypass if they did not upgrade to builds that fix both

Discovery

Identified by security researchers examining ManageEngine ServiceDesk Plus REST API security. Reported and patched in August 2021.

Exploitation Context

ManageEngine IT management products have been recurring targets for APT groups due to their privileged access to enterprise IT infrastructure. ServiceDesk Plus with unauthenticated REST API access exposes help desk data and potentially enables enumeration of users, assets, and IT configurations that facilitate further attacks. The CISA KEV addition in December 2021 reflects confirmed exploitation in the wild.

Remediation

  1. Upgrade ServiceDesk Plus to Build 11302 or later (also upgrade to Build 11306 to address the subsequent CVE-2021-44077 file upload RCE)
  2. Restrict ServiceDesk Plus web interface access to internal/VPN-connected users only
  3. Review ServiceDesk Plus REST API access logs for unauthenticated requests during the vulnerable period
  4. Audit ticket contents and exported data for potential unauthorized access
  5. Rotate credentials for any service accounts used by ServiceDesk Plus for AD integration

Key Details

PropertyValue
CVE ID CVE-2021-37415
Vendor / Product Zoho — ManageEngine ServiceDesk Plus (SDP)
NVD Published2021-09-01
NVD Last Modified2025-10-31
CVSS 3.1 Score9.8
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-306 find similar ↗
CISA KEV Added2021-12-01
CISA KEV Deadline2021-12-15
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2021-12-15. Apply updates per vendor instructions.

Timeline

DateEvent
2021-08-10ManageEngine releases ServiceDesk Plus Build 11302 with fix for CVE-2021-37415
2021-09-01CVE published
2021-12-01Added to CISA Known Exploited Vulnerabilities catalog
2021-12-15CISA BOD 22-01 remediation deadline

References

ResourceType
ManageEngine ServiceDesk Plus Release Notes Vendor Advisory
NVD — CVE-2021-37415 Vulnerability Database
CISA KEV Catalog Entry US Government