PT-2013-4209 · Microsoft · Active Directory Federation Services
Published
2013-08-14
·
Updated
2020-09-28
·
CVE-2013-3185
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Active Directory Federation Services (AD FS) versions 1.x through 2.1
Description
The issue allows remote attackers to obtain sensitive information about the service account, and possibly conduct account-lockout attacks, by connecting to an endpoint.
Recommendations
For Microsoft Active Directory Federation Services (AD FS) versions 1.x through 2.1, update to a version that is not affected by this issue to prevent information disclosure and potential account-lockout attacks.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Active Directory Federation Services