CVE-2021-33617: Medium severity manageengine password manager pro vulnerability
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33617?
The severity of CVE-2021-33617 is medium with a severity value of 5.3.
What is affected by CVE-2021-33617?
Zoho ManageEngine Password Manager Pro versions up to and including 11.2 are affected by CVE-2021-33617.
What is the vulnerability in Zoho ManageEngine Password Manager Pro?
The vulnerability in Zoho ManageEngine Password Manager Pro is username enumeration via the login/AjaxResponse.jsp endpoint.
How can an attacker exploit CVE-2021-33617?
An attacker can exploit CVE-2021-33617 by enumerating valid usernames through the login/AjaxResponse.jsp endpoint.
Is there a patch available for CVE-2021-33617?
Yes, a patch is available for CVE-2021-33617. It is recommended to update to version 11.2 11200 or higher of Zoho ManageEngine Password Manager Pro.