CVE-2021-20081: Critical severity manageengine servicedesk plus vulnerability
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20081?
CVE-2021-20081 is a vulnerability in ManageEngine ServiceDesk Plus before version 11205 that allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
How severe is CVE-2021-20081?
CVE-2021-20081 has a severity rating of 7.2 (Critical).
What software is affected by CVE-2021-20081?
ManageEngine ServiceDesk Plus versions up to 11.2 are affected by CVE-2021-20081.
How can an attacker exploit CVE-2021-20081?
An attacker can exploit CVE-2021-20081 by sending disallowed inputs to the vulnerable ManageEngine ServiceDesk Plus software, allowing them to execute arbitrary commands with SYSTEM privileges.
Is there a fix for CVE-2021-20081?
Yes, upgrading to version 11205 of ManageEngine ServiceDesk Plus will fix the CVE-2021-20081 vulnerability.