CVE-2021-33617
About
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
Rainforest analyst review
Zoho ManageEngine Password Manager Pro leaks a yes/no signal about whether a username exists: a specific login endpoint returns a null response only when the username is invalid, so an attacker can enumerate valid accounts by watching for that difference. No credentials are disclosed and nothing is executed — the impact is confidentiality of the account list, which is a reconnaissance aid rather than a break-in.
What gives this more weight than a typical username-enumeration bug is the product it's in: Password Manager Pro is, by definition, the vault. A confirmed list of valid administrator usernames is exactly the input an attacker wants before mounting credential-stuffing or password-spraying against that same portal. So while the flaw itself is low-severity and unauthenticated-but-harmless in isolation, it meaningfully sharpens a follow-on brute-force campaign against a high-value target.
Our angle is chaining and exposure rather than the bug in isolation. PMP consoles should not be internet-facing, so the first check is whether any pre-11.2 instance is reachable from outside — an exposed vault login is where enumeration plus spraying becomes a plausible sequence. Where it's internal-only, we rank the enumeration flaw low and fold it into normal patching, while making sure rate-limiting and lockout on the login endpoint are doing their job to blunt the attack it enables.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2021-33617?
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
How severe is CVE-2021-33617?
CVE-2021-33617 carries a CVSS 3.1 base score of 5.3, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 60 out of 100, in the elevated band.
How is CVE-2021-33617 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality Low, integrity None and availability None.
Which products are affected by CVE-2021-33617?
Public advisories list the following as affected: manageengine password manager pro. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2021-33617?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
