Security Advisory

CVE-2021-33617

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-07-31 16:55:50
Last updated 2024-08-03 23:58:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.