AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-20147

MEDIUM · CVSS 5.3 EPSS 6.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-20147
Severity
MEDIUM
CVSS
5.3
EPSS
6.90%
Windows

Original NVD Description

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.