CVE-2021-33617

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2021
Last modified:
10/08/2021

Description

Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:* 11.2 (excluding)
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:11.2:-:*:*:*:*:*:*