CVE-2021-44077
CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Affected Products
manageengine servicedesk pluszohocorpmanageengine servicedesk plus mspzohocorpmanageengine supportcenter pluszohocorpResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP be…
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP be…
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP be…
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP be…
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP be…
Frequently Asked Questions
Is CVE-2021-44077 in your stack?
O3 detects CVE-2021-44077 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.