Medium severity5.3NVD Advisory· Published Jul 31, 2021· Updated Jun 17, 2026
CVE-2021-33617
CVE-2021-33617
Description
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*range: <11.2
- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:11.2:-:*:*:*:*:*:*
- Zoho/ManageEngine Password Manager Prodescription
- Range: <11.2 11200
- Range: <11.2 11200
Patches
Vulnerability mechanics
References
3- herolab.usd.de/security-advisories/usd-2021-0015/nvdExploitThird Party Advisory
- www.manageengine.comnvdVendor Advisory
- www.manageengine.com/products/passwordmanagerpro/release-notes.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.