2.1

CVE-2002-0507

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftExchange Server Version5.5 Update-
MicrosoftExchange Server Version5.5 Updatesp1
MicrosoftExchange Server Version5.5 Updatesp2
MicrosoftExchange Server Version5.5 Updatesp3
MicrosoftExchange Server Version5.5 Updatesp4
MicrosoftExchange Server Version2000 Update-
MicrosoftExchange Server Version2000 Updatesp1
MicrosoftExchange Server Version2000 Updatesp2
RsaSecurid Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.34% 0.794
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.