Active Directory
A set of directory-based technologies included in Windows Server.
6,933 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Issue description:
Username and password on ADFS login page are not encrypted.
Examples:
1, When we input username and password on ADFS login page, we can see plaintext of username/password via F12
2, We can also capture plaintext of username/password via Burp Suite tool.
Background:
As our product integrated ADFS, our customer can not accept the security issue, please take high priority to fix it, thanks.
If need more information, please contact my mail: ******@siemens.com
Dear Microsoft team, Any comments for the topic? thanks.