First published: Thu Jun 10 2021(Updated: )
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <11.2 | |
Zohocorp Manageengine Servicedesk Plus | =11.2 | |
Zohocorp Manageengine Servicedesk Plus | =11.2-build11201 | |
Zohocorp Manageengine Servicedesk Plus | =11.2-build11202 | |
Zohocorp Manageengine Servicedesk Plus | =11.2-build11203 | |
Zohocorp Manageengine Servicedesk Plus | =11.2-build11204 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20081 is a vulnerability in ManageEngine ServiceDesk Plus before version 11205 that allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
CVE-2021-20081 has a severity rating of 7.2 (Critical).
ManageEngine ServiceDesk Plus versions up to 11.2 are affected by CVE-2021-20081.
An attacker can exploit CVE-2021-20081 by sending disallowed inputs to the vulnerable ManageEngine ServiceDesk Plus software, allowing them to execute arbitrary commands with SYSTEM privileges.
Yes, upgrading to version 11205 of ManageEngine ServiceDesk Plus will fix the CVE-2021-20081 vulnerability.