First published: Tue Sep 18 2018(Updated: )
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Active Directory Federation Services | <=4.0 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16794 has a medium severity rating due to the potential for SSRF attacks allowing an attacker to send requests to internal resources.
To fix CVE-2018-16794, update Microsoft ADFS to the latest version that addresses this SSRF vulnerability.
CVE-2018-16794 affects Microsoft ADFS versions up to and including 4.0.
CVE-2018-16794 is related specifically to Microsoft ADFS 4.0, which can be deployed on Windows Server 2016.
The impact of CVE-2018-16794 can lead to unauthorized access to internal systems due to Server-Side Request Forgery capabilities.