An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
2002-08-12T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | exchange_server | 5.5 | Yes |
Application | microsoft | exchange_server | 5.5 | Yes |
Application | microsoft | exchange_server | 5.5 | Yes |
Application | microsoft | exchange_server | 5.5 | Yes |
Application | microsoft | exchange_server | 5.5 | Yes |
Application | microsoft | exchange_server | 2000 | Yes |
Application | microsoft | exchange_server | 2000 | Yes |
Application | microsoft | exchange_server | 2000 | Yes |
Hardware | rsa | securid | 5.0 | Yes |