Due to inproper permissions verification when submitting a password modify request, a normal user can successfully change any user's Windows 2000 domain login password. This is accomplished if LDAP requests are being made over a SSL session.
Due to inproper permissions verification when submitting a password modify request, a normal user can successfully change any user's Windows 2000 domain login password. This is accomplished if LDAP requests are being made over a SSL session.