Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
2018-09-21T16:29:01.483
2024-11-21T03:53:21.863
Modified
CVSSv3.0: 8.6 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |
Application | microsoft | exchange_server | 2010 | Yes |