Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exchange_server | Microsoft | * | 5.5 (including) |