8.6

CVE-2018-16793

Exploit

Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftExchange Server Version2010 Updatesp3_rollup1
MicrosoftExchange Server Version2010 Updatesp3_rollup10
MicrosoftExchange Server Version2010 Updatesp3_rollup11
MicrosoftExchange Server Version2010 Updatesp3_rollup12
MicrosoftExchange Server Version2010 Updatesp3_rollup13
MicrosoftExchange Server Version2010 Updatesp3_rollup14
MicrosoftExchange Server Version2010 Updatesp3_rollup15
MicrosoftExchange Server Version2010 Updatesp3_rollup16
MicrosoftExchange Server Version2010 Updatesp3_rollup17
MicrosoftExchange Server Version2010 Updatesp3_rollup18
MicrosoftExchange Server Version2010 Updatesp3_rollup2
MicrosoftExchange Server Version2010 Updatesp3_rollup3
MicrosoftExchange Server Version2010 Updatesp3_rollup4
MicrosoftExchange Server Version2010 Updatesp3_rollup5
MicrosoftExchange Server Version2010 Updatesp3_rollup6
MicrosoftExchange Server Version2010 Updatesp3_rollup7
MicrosoftExchange Server Version2010 Updatesp3_rollup8
MicrosoftExchange Server Version2010 Updatesp3_rollup9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.76% 0.724
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.