First published: Mon Jan 03 2022(Updated: )
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <=6.0 | |
ADSelfService Plus | =6.1 | |
ADSelfService Plus | =6.1-6100 | |
ADSelfService Plus | =6.1-6101 | |
ADSelfService Plus | =6.1-6102 | |
ADSelfService Plus | =6.1-6103 | |
ADSelfService Plus | =6.1-6104 | |
ADSelfService Plus | =6.1-6105 | |
ADSelfService Plus | =6.1-6106 | |
ADSelfService Plus | =6.1-6107 | |
ADSelfService Plus | =6.1-6108 | |
ADSelfService Plus | =6.1-6109 | |
ADSelfService Plus | =6.1-6110 | |
ADSelfService Plus | =6.1-6111 | |
ADSelfService Plus | =6.1-6112 | |
ADSelfService Plus | =6.1-6113 | |
ADSelfService Plus | =6.1-6114 | |
ADSelfService Plus | =6.1-6115 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this ManageEngine ADSelfService Plus vulnerability is CVE-2021-20148.
The severity of CVE-2021-20148 is medium with a CVSS score of 4.3.
This vulnerability affects ManageEngine ADSelfService Plus versions below build 6116.
This vulnerability allows a user from one domain to obtain the password policy for another domain.
Yes, updating ManageEngine ADSelfService Plus to build 6116 or higher will fix this vulnerability.