First published: Fri Sep 10 2021(Updated: )
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.0.709 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37414 is a vulnerability in Zoho ManageEngine DesktopCentral before version 10.0.709 that allows anyone to obtain a valid user's APIKEY without authentication.
CVE-2021-37414 has a severity rating of 7.5 (high).
CVE-2021-37414 allows unauthorized individuals to obtain a valid user's APIKEY without authentication, potentially exposing sensitive data and allowing unauthorized access to the application.
The affected software is Zoho ManageEngine DesktopCentral version up to 10.0.709.
To fix CVE-2021-37414, update Zoho ManageEngine DesktopCentral to version 10.0.709 or later.