Beveiligingsadvies

CVE-2021-20147

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-01-03 21:07:10
Laatst bijgewerkt 2024-08-03 17:30:07
Toegewezen door tenable
CVSS-score geen score
Status PUBLISHED

Beschrijving

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.