Application Set Enumeration Still Possible After Changing Users' Passwords
Application Set Enumeration Still Possible After Changing Users' Passwords Application Set Enumeration Still Possible After Changing Users' Passwords
Citrix states in their article: CTX110296
Document ID: CTX110296, Created on: Jul 5, 2006, Updated: Jul 10, 2006
Products: Citrix Presentation Server 4.0 for Microsoft Windows 2003, Citrix Presentation Server 4.0 for Microsoft Windows 2000, Citrix MetaFrame XP 1.0 for Microsoft Windows 2000, Citrix MetaFrame XP 1.0 for Microsoft Windows 2003, Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2000, Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2003, ICA Win32 Program Neighborhood Client
Symptoms
With any version of Program Neighborhood Classic, enumeration of an application set still occurs after changing a user’s password, without re-prompting for credentials. However, the user is not able to launch an application with the previous password.
Reproduction
Create an application set in Program Neighborhood.
Authenticate to the application set. The list of published applications is displayed.
Go to Active Directory/User Management and change the user’s password.
Refresh the application set or close Program Neighborhood. The list of published applications are displayed without re-prompting for credentials.
Cause
An existing logon session that has already been authenticated does not require a re-prompt for credentials, even if the password has changed.
When launching an application however, a new logon session on to the server must be created, and users are re-prompted for their credentials.
Resolution
This is as designed.
User login
Who's new
- Choodogek
- zepsleltpap
- layersepavy
- moneytome12
- maczugaher