Unrated severityNVD Advisory· Published Jan 3, 2022· Updated Aug 3, 2024
CVE-2021-20148
CVE-2021-20148
Description
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ManageEngine/ADSelfService Plusdescription
- Range: <6116 Build
Patches
Vulnerability mechanics
References
1- www.tenable.com/security/research/tra-2021-52mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.