First published: Mon May 12 2008(Updated: )
Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook Web Access |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2143 has a medium severity rating due to the potential for sensitive information exposure.
To fix CVE-2008-2143, ensure that Microsoft Outlook Web Access is configured to use the correct Cache-Control directives.
CVE-2008-2143 affects unspecified versions of Microsoft Outlook Web Access that incorrectly use the Cache-Control: no-cache directive.
The potential risks of CVE-2008-2143 include the unintended caching of sensitive information by web browsers.
Yes, later versions of Microsoft Outlook Web Access may have addressed CVE-2008-2143 through updates or configuration changes.