8.6
CVE-2018-16793
- EPSS 0.76%
- Veröffentlicht 21.09.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:21
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup1
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup10
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup11
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup12
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup13
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup14
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup15
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup16
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup17
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup18
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup2
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup3
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup4
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup5
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup6
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup7
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup8
Microsoft ≫ Exchange Server Version2010 Updatesp3_rollup9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.76% | 0.724 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.6 | 3.9 | 4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.