CVE-2021-20147

MEDIUM

ManageEngine ADSelfService Plus < 6.0 - Unauthenticated User Enumeration via UMCP ChangePasswordAPI

Title source: llm
STIX 2.1

Description

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2021-52

Scores

CVSS v3 5.3
EPSS 0.1803
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (2)
zohocorp/manageengine_adselfservice_plus 6.1 (17 CPE variants)
zohocorp/manageengine_adselfservice_plus < 6.0
Published Jan 03, 2022
Tracked Since Feb 18, 2026