|
Microsoft ISA Server HTTP/HTTPS Service Basic Auth Information Disclosure Vulnerability
Microsoft Internet Security and Acceleration (ISA) server is prone to an information disclosure vulnerability. Reports indicate that the issue manifests when an ISA server is publishing a Web service that has Basic authentication enabled, but the Web publishing rules that process the request are configured as 'SSL required'. An attacker that has the ability to intercept network communications between the ISA server and a client may leverage this issue to obtain Web site authentication credentials. |
|
|
Privacy Statement |