Data Mining Possible Using Subtree Search for AdsPath and SYS_RDN Only (216401)
The information in this article applies to:
- Microsoft Site Server 3.0
This article was previously published under Q216401 SYMPTOMS
When you perform a subtree search and only search for adsPath and
SYS_RDN, the security check for inherited ACEs may be performed after
returning the first match. The first row makes it by the security
check, despite the lack of permissions.
RESOLUTION
To resolve this problem, apply the latest Site Server 3.0 service pack.
WORKAROUND
To work around this problem, set an absolute (physical) ACL on each and
every object itself.
STATUS
Microsoft has confirmed this to be a problem in Site Server version 3.0. This problem has been corrected in the
latest U.S. service pack for Site Server version 3.0. For information on obtaining the service pack, query on the
following word in the Microsoft Knowledge Base (without the spaces):
Modification Type: | Major | Last Reviewed: | 8/27/2002 |
---|
Keywords: | kbbug kbSiteServer300sp2fix KB216401 |
---|
|