Lucene search

K
cvelistTenableCVELIST:CVE-2021-20147
HistoryJan 03, 2022 - 9:07 p.m.

CVE-2021-20147

2022-01-0321:07:10
tenable
www.cve.org
4
manageengine
adselfservice plus
umcp
vulnerability
remote attacker
windows domain user

AI Score

5.6

Confidence

High

EPSS

0.007

Percentile

80.5%

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

CNA Affected

[
  {
    "product": "ManageEngine ADSelfService Plus",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "< 6116"
      }
    ]
  }
]

AI Score

5.6

Confidence

High

EPSS

0.007

Percentile

80.5%

Related for CVELIST:CVE-2021-20147