CVE Vulnerabilities

CVE-2002-0507

Improper Authentication

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Exchange_serverMicrosoft5.5 (including)5.5 (including)
Exchange_serverMicrosoft5.5-sp1 (including)5.5-sp1 (including)
Exchange_serverMicrosoft5.5-sp2 (including)5.5-sp2 (including)
Exchange_serverMicrosoft5.5-sp3 (including)5.5-sp3 (including)
Exchange_serverMicrosoft5.5-sp4 (including)5.5-sp4 (including)
Exchange_serverMicrosoft2000 (including)2000 (including)
Exchange_serverMicrosoft2000-sp1 (including)2000-sp1 (including)
Exchange_serverMicrosoft2000-sp2 (including)2000-sp2 (including)

Potential Mitigations

References