Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
References
Link | Resource |
---|---|
http://www.us-cert.gov/ncas/alerts/TA13-134A | Third Party Advisory US Government Resource |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16741 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040 |
Configurations
Information
Published : 2013-05-14 20:36
Updated : 2018-10-12 15:04
NVD link : CVE-2013-1337
Mitre link : CVE-2013-1337
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
microsoft
- .net_framework