CVE-2020-35682

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
𝑥
< 11.1
zohocorpmanageengine_servicedesk_plus
11.1:11100
zohocorpmanageengine_servicedesk_plus
11.1:11101
zohocorpmanageengine_servicedesk_plus
11.1:11102
zohocorpmanageengine_servicedesk_plus
11.1:11103
zohocorpmanageengine_servicedesk_plus
11.1:11104
zohocorpmanageengine_servicedesk_plus
11.1:11105
zohocorpmanageengine_servicedesk_plus
11.1:11106
zohocorpmanageengine_servicedesk_plus
11.1:11107
zohocorpmanageengine_servicedesk_plus
11.1:11108
zohocorpmanageengine_servicedesk_plus
11.1:11109
zohocorpmanageengine_servicedesk_plus
11.1:11110
zohocorpmanageengine_servicedesk_plus
11.1:11111
zohocorpmanageengine_servicedesk_plus
11.1:11112
zohocorpmanageengine_servicedesk_plus
11.1:11113
zohocorpmanageengine_servicedesk_plus
11.1:11114
zohocorpmanageengine_servicedesk_plus
11.1:11115
zohocorpmanageengine_servicedesk_plus
11.1:11116
zohocorpmanageengine_servicedesk_plus
11.1:11117
zohocorpmanageengine_servicedesk_plus
11.1:11118
zohocorpmanageengine_servicedesk_plus
11.1:11119
zohocorpmanageengine_servicedesk_plus
11.1:11120
zohocorpmanageengine_servicedesk_plus
11.1:11121
zohocorpmanageengine_servicedesk_plus
11.1:11122
zohocorpmanageengine_servicedesk_plus
11.1:11123
zohocorpmanageengine_servicedesk_plus
11.1:11124
zohocorpmanageengine_servicedesk_plus
11.1:11125
zohocorpmanageengine_servicedesk_plus
11.1:11126
zohocorpmanageengine_servicedesk_plus
11.1:11127
zohocorpmanageengine_servicedesk_plus
11.1:11128
zohocorpmanageengine_servicedesk_plus
11.1:11129
zohocorpmanageengine_servicedesk_plus
11.1:11130
zohocorpmanageengine_servicedesk_plus
11.1:11131
zohocorpmanageengine_servicedesk_plus
11.1:11132
zohocorpmanageengine_servicedesk_plus
11.1:11133
𝑥
= Vulnerable software versions