CVE-2020-35682

Severity
8.8HIGH
EPSS
1.7%
top 17.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 24

Description

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-8c7x-fqjf-h7q7: Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login)2022-05-24
CVEList
CVE-2020-35682: Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login)2021-03-13
CVE-2020-35682 (HIGH CVSS 8.8) | Zoho ManageEngine ServiceDesk Plus | cvebase.io