4.3

CVE-2021-20148

Exploit

ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Adselfservice Plus Version6.1 Update-
ZohocorpManageengine Adselfservice Plus Version6.1 Update6100
ZohocorpManageengine Adselfservice Plus Version6.1 Update6101
ZohocorpManageengine Adselfservice Plus Version6.1 Update6102
ZohocorpManageengine Adselfservice Plus Version6.1 Update6103
ZohocorpManageengine Adselfservice Plus Version6.1 Update6104
ZohocorpManageengine Adselfservice Plus Version6.1 Update6105
ZohocorpManageengine Adselfservice Plus Version6.1 Update6106
ZohocorpManageengine Adselfservice Plus Version6.1 Update6107
ZohocorpManageengine Adselfservice Plus Version6.1 Update6108
ZohocorpManageengine Adselfservice Plus Version6.1 Update6109
ZohocorpManageengine Adselfservice Plus Version6.1 Update6110
ZohocorpManageengine Adselfservice Plus Version6.1 Update6111
ZohocorpManageengine Adselfservice Plus Version6.1 Update6112
ZohocorpManageengine Adselfservice Plus Version6.1 Update6113
ZohocorpManageengine Adselfservice Plus Version6.1 Update6114
ZohocorpManageengine Adselfservice Plus Version6.1 Update6115
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.437
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.