CVE-2002-0507: Low severity Microsoft Exchange Server vulnerability
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0507?
CVE-2002-0507 is considered a high severity vulnerability due to its potential to bypass authentication mechanisms.
How do I fix CVE-2002-0507?
To fix CVE-2002-0507, you should update your Microsoft Exchange Server to the latest service pack that addresses this vulnerability.
What systems are affected by CVE-2002-0507?
CVE-2002-0507 affects Microsoft Exchange Server versions 5.5 and 2000, specifically certain service packs.
Can CVE-2002-0507 be exploited remotely?
Yes, CVE-2002-0507 can be exploited locally by users who have access to the OWA interface.
What are the risks associated with CVE-2002-0507?
The risks associated with CVE-2002-0507 include unauthorized access to user accounts and the potential for sensitive data exposure.