← Back to CVE List

CVE-2021-20147

Published: 2022-01-03T22:15Z
Last Modified: 2024-11-21T05:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt