CVE-2021-20147 is a medium-severity vulnerability affecting ManageEngine ADSelfService Plus builds below 6116, allowing an unauthenticated remote attacker to determine the existence of Windows domain users. This information disclosure vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality and no impact on integrity or availability, with no user interaction required. While no active exploitation or public exploit code has been observed, and community discussion is minimal, organizations using affected versions should consider patching to mitigate this information leakage risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:-:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6100:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6101:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6102:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ManageEngine SelfService Plus Multiple Vulnerabilities
Dec 23, 2021ManageEngine SelfService Plus Multiple Vulnerabilities
Dec 23, 2021ManageEngine SelfService Plus Multiple Vulnerabilities
Dec 23, 2021