6.1
CVE-2017-8621
- EPSS 3.17%
- Veröffentlicht 11.07.2017 21:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2010 Update sp3
Microsoft ≫ Exchange Server Version 2013 Update cumulative_update_16
Microsoft ≫ Exchange Server Version 2013 Update sp1
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.17% | 0.864 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
http://www.securitytracker.com/id/1038852
http://www.securityfocus.com/bid/99533
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8621