November 3, 2021 · Applied Cybernetics Group
CVE-2019-8394 — Zoho ManageEngine
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Zoho
- Product
- ManageEngine
- EPSS
- 99.5th percentile (score 0.875, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-8394
CISA short description
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
Required action
Apply updates per vendor instructions.