ZeroHour

CVE-2021-20147

PoC
CVSS 3.1
5.3 medium
EPSS
7%p94
Published
()
Modified
Description

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

Vendors
zohocorp
Products
manageengine adselfservice plus
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.