VulnerabilityModified
CVE-2021-20147
This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
MEDIUM 5.3EPSS 6.90%
Does this matter?
Lower severity and a low EPSS score (6.90%). Track it; it rarely justifies an emergency change on its own.
Description
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 6.90% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- vulnreport@tenable.com
References
- https://www.tenable.com/security/research/tra-2021-52Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-52Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.