Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j385-q64g-xhxj

Опубликовано: 04 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

EPSS

Процентиль: 95%
0.18027
Средний

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.3
nvd
около 4 лет назад

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

EPSS

Процентиль: 95%
0.18027
Средний

Дефекты

CWE-203