Description: When publishing a Web server using forms-based authentication with Radius one-time password (OTP ) as the credentials authority and Kerberos constrained delegation, it may be possible to bypass the form authentication and log on using invalid credentials.
Architecture: n/a
Classification: Security Updates
Supported products: Internet Security and Acceleration Server 2006
Supported languages: Chinese (Traditional) , German , English , Spanish , French , Italian , Japanese , Korean , Portuguese (Brazil) , Russian , Chinese (Simplified)
MSRC Number: MS09-031
MSRC severity: Important
KB article numbers: 970811