CVE-2021-20147: Medium severity adselfservice plus vulnerability
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20147?
CVE-2021-20147 is a vulnerability in ManageEngine ADSelfService Plus below build 6116 that allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
What is the severity of CVE-2021-20147?
The severity of CVE-2021-20147 is medium, with a severity value of 5.3.
How does CVE-2021-20147 affect ManageEngine ADSelfService Plus?
CVE-2021-20147 affects ManageEngine ADSelfService Plus below build 6116.
How can an attacker exploit CVE-2021-20147?
An attacker can exploit CVE-2021-20147 by sending requests to the UMCP operation of the ChangePasswordAPI and observing the response discrepancy to determine the existence of a Windows domain user.
Where can I find more information about CVE-2021-20147?
You can find more information about CVE-2021-20147 at the following link: [CVE-2021-20147](https://www.tenable.com/security/research/tra-2021-52)