2.1
CVE-2002-0507
- EPSS 2.22%
- Veröffentlicht 12.08.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:57:34
- Erkennungen
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 5.5 Update -
Microsoft ≫ Exchange Server Version 5.5 Update sp1
Microsoft ≫ Exchange Server Version 5.5 Update sp2
Microsoft ≫ Exchange Server Version 5.5 Update sp3
Microsoft ≫ Exchange Server Version 5.5 Update sp4
Microsoft ≫ Exchange Server Version 2000 Update -
Microsoft ≫ Exchange Server Version 2000 Update sp1
Microsoft ≫ Exchange Server Version 2000 Update sp2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.22% | 0.803 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://online.securityfocus.com/archive/1/264705
http://www.iss.net/security_center/static/8681.php
http://www.securityfocus.com/bid/4390