← Back to browse · API

CVE-2021-44077

Severity
CRITICAL
CVSS
9.8
EPSS
0.93514
Risk score
57.73
CISA KEV
Yes
PoC
No
Published
2021-11-29
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-30936, GHSA-XM89-VXJX-JVCG
Products
Zoho:ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus, n/a:n/a n/a
Sources
cisa.gov CVE-2021-44077
euvd EUVD-2021-30936

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

References