CVE-2018-16794: SSRF
Published Sep 18, 2018
·Updated
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
Affected Software
2 affected components
Microsoft Active Directory Federation Services<=4.0
Microsoft Windows Server 2016
Event History
Sep 18, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16794?
CVE-2018-16794 has a medium severity rating due to the potential for SSRF attacks allowing an attacker to send requests to internal resources.
2
How do I fix CVE-2018-16794?
To fix CVE-2018-16794, update Microsoft ADFS to the latest version that addresses this SSRF vulnerability.
3
What are the affected versions for CVE-2018-16794?
CVE-2018-16794 affects Microsoft ADFS versions up to and including 4.0.
4
Is CVE-2018-16794 present in Windows Server 2016?
CVE-2018-16794 is related specifically to Microsoft ADFS 4.0, which can be deployed on Windows Server 2016.
5
What impact does CVE-2018-16794 have on systems?
The impact of CVE-2018-16794 can lead to unauthorized access to internal systems due to Server-Side Request Forgery capabilities.