First published: Sat Mar 13 2021(Updated: )
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <11.1 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11100 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11101 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11102 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11103 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11104 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11105 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11106 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11107 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11108 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11109 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11110 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11111 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11112 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11113 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11114 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11115 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11116 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11117 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11118 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11119 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11120 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11121 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11122 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11123 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11124 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11125 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11126 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11127 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11128 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11129 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11130 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11131 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11132 | |
Zohocorp Manageengine Servicedesk Plus | =11.1-11133 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35682 is high with a severity value of 8.8.
Zoho ManageEngine ServiceDesk Plus versions up to 11.1-11133 are affected by CVE-2020-35682.
CVE-2020-35682 allows an Authentication Bypass only during SAML login.
To fix CVE-2020-35682, update Zoho ManageEngine ServiceDesk Plus to version 11.1-11134 or higher.
You can find more information about CVE-2020-35682 at the following link: [https://www.manageengine.com/products/service-desk/on-premises/readme.html#11134](https://www.manageengine.com/products/service-desk/on-premises/readme.html#11134)