CVE-2015-1632: XSS
Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1632?
CVE-2015-1632 has a critical severity rating as it allows remote attackers to execute arbitrary web scripts via Cross-site Scripting (XSS).
How do I fix CVE-2015-1632?
To fix CVE-2015-1632, apply the latest security updates provided by Microsoft for Exchange Server 2013 SP1 and Cumulative Update 7.
What versions of Microsoft Exchange Server are affected by CVE-2015-1632?
CVE-2015-1632 affects Microsoft Exchange Server 2013 SP1 and Cumulative Update 7.
What type of vulnerability is CVE-2015-1632?
CVE-2015-1632 is classified as a Cross-Site Scripting (XSS) vulnerability.
Is CVE-2015-1632 exploitable remotely?
Yes, CVE-2015-1632 can be exploited remotely by attackers through the affected web application.