← Vulnerability feed

Vulnerability record · CVE-2021-31159 · published 16 June 2021

CVE-2021-31159: Zohocorp manageengine servicedesk plus msp error message information leak vulnerability

Zohocorp · Manageengine Servicedesk Plus Msp

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

5.3 CVSS 3.1 Medium EPSS 18% · top 2.9% CWE-209 · Error message information leak
5.3CVSS 3.1 base score, v2 5.0
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-44675Zohocorp manageengine servicedesk plus msp improper authentication vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…EPSS 6.5%9.8CVE-2021-31531Zohocorp manageengine servicedesk plus msp server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).EPSS 2.4%9.1CVE-2023-22964Zohocorp manageengine servicedesk plus msp improper authentication vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.EPSS 2.4%8.8CVE-2022-40773Zohocorp manageengine servicedesk plus msp improper input validation vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to …EPSS 4.8%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%7.5CVE-2023-26601Zohocorp manageengine assetexplorer uncontrolled resource consumption vulnerabilityZoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 1400…EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2021-31159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.