SP question : Microsoft IIS ISAPI Extension Enumerate Root Web Server Directory Vulnerability
Lee, Dong
DLee at umaryland.edu
Tue Jun 3 18:32:31 UTC 2025
Good afternoon,
Rapid7 reported a vulnerability in Microsoft IIS, identified as the "ISAPI Extension Enumerate Root Web Server Directory Vulnerability," which may allow unauthorized directory enumeration.
The report suggests remediating a vulnerability by enabling ISAPI mappings in IIS, specifically by navigating to Edit -> Request Restrictions and checking "Invoke handler only if request is mapped to: File." I researched the impact of this change and found that it may negatively affect the Shibboleth Service Provider (SP) because it relies on virtual paths (e.g., /Shibboleth.sso/Login) rather than physical files. However, I could not confirm this information. Can you validate whether this is correct? If true, what would be a suitable solution to address the vulnerability while maintaining SP functionality?
Thank you,
Dong Lee
Identity Management & System Integration
Center for Information Technology Services
University of Maryland, Baltimore
410-706-3027
dlee at umaryland.edu<mailto:dlee at umaryland.edu>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250603/377b3974/attachment.htm>
More information about the users
mailing list