vendor:
ADSelfService Plus
by:
Metin Yunus Kandemir
3.1
CVSS
LOW
User Enumeration
200
CWE
Product Name: ADSelfService Plus
Affected Version From: Build 6118
Affected Version To: Build 6121
Patch Exists: NO
Related CWE:
CPE: a:manageengine:adselfservice_plus:6.1
Platforms Tested: Windows, Linux, Mac
2020
ManageEngine ADSelfService Plus 6.1 – User Enumeration
The domain users can be enumerated like userenum module of the kerbrute tool using this exploit. If you conducted a brute-force attack against a user, please run the script after 30 minutes (default settings) otherwise the results can be false positive.
Mitigation:
Ensure that the application is configured to prevent user enumeration.