[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MS Exchange / OWA NTLM Authentication Vulnerability

ID: oval:org.mitre.oval:def:477Date: (C)2004-01-20   (M)2021-06-02
Class: VULNERABILITYFamily: windows




Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.

Platform:
Microsoft Windows 2000
Microsoft Windows Server 2003
Product:
Microsoft Exchange Server
Reference:
CVE-2003-0904
CVE    1
CVE-2003-0904

© SecPod Technologies