Article ID: 316838 - Last Review: October 27, 2006 - Revision: 3.3 An Update Is Available for BackOffice Server 4.0 and 4.5 for Logging OnThis article was previously published under Q316838 SYMPTOMS
An update is available for the BackOffice Web Administrator component of BackOffice Server versions 4.0 and 4.5. This update is for installations in which the default security settings have been changed. If the default security settings for the Boadmin virtual folder have been changed, apply this update to avoid a possible security risk. Mitigating factors:
CAUSE
The issue occurs because users can bypass the logon screen (Boadmin\Backoffice\Services.asp) if an authorization type (auth_type) other than "" is entered as part of an HTTP request.
RESOLUTIONThe following file is available for download from the Microsoft Download Center: Collapse this image ![]() For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
The English version of this fix should have the following file attributes or later: Date Time Size File name --------------------------------------- 11-Jan-2002 23:34 19,965 Include.asp WORKAROUND
To prevent the issue that is mentioned in this article from occurring, download the fix that is mentioned in the "Resolution" section of this article, or use the following procedure:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. MORE INFORMATION
If you do not use the BackOffice Web Administrator component to manage your BackOffice server, you can safely delete the Web site from your BackOffice server. To do this:
| Article Translations
|
Back to the top

