サポートと今すぐチャット
サポートとのチャット
セルフ・サービス・ツール
ナレッジベース
マイ アカウント
通知および警告
製品別サポート
ソフトウェアのダウンロード
技術文書
ユーザーフォーラム
ビデオチュートリアル
RSSフィード
サポートの基本要素
受賞歴とお客様の声
ライセンス契約
サポートガイド

Active Roles 製品のお知らせ

戻る
Critical Alerts
Critical Notification

Active Roles 7.4.x and 7.5.x

 

A security vulnerability was discovered in one of the authentication components that may be used when logging into the Active Roles Web Interface. This vulnerability could allow an attacker to gain unauthorized access. 

How does this affect me?

If you have installed and configured the Redistributable STS component by following the section located in Appendix E of the Active Roles Administration Guide (versions 7.4.x and 7.5) and your users authenticate against an identity provider STS such as Microsoft ADFS, Microsoft Azure AD, Okta, or Ping Federate you may be affected by this security vulnerability.

Resolution 

A security fix has been released for Active Roles 7.4.x and 7.5. if you have installed and configured the Redistribute STS component as described above, we recommend this patch be applied. 

If you have not installed the Redistributable STS and are using the default IIS Windows authentication to log into the Active Roles Web Interface, you would not be affected.

Status

A hotfix for Active Roles versions 7.4.x and 7.5 is now available. Please review KB 337963 for further details on this issue. 

We apologize for the inconvenience this issue may have caused.