Vulnerability Name: | CCN-7039 | ||||||
Published: | 2001-08-22 | ||||||
Updated: | 2001-08-22 | ||||||
Summary: | Microsoft Exchange Server using the Outlook Web Access (OWA) service are vulnerable to a denial of service attack. If a remote attacker enters a long string of "%" characters in the login field of the OWA page, and also enters a long string of "%" characters for the username and password in the NT challenge dialog box, the attacker can cause the IIS Administration and Web Publishing services to fail. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Aug 22 2001 - 17:22:17 CDT OWA over ssl shutting down IIS Source: CCN Type: BugTraq Mailing List, Thu Aug 23 2001 - 04:47:17 CDT RE: OWA over ssl shutting down IIS Source: CCN Type: BugTraq Mailing List, Sat Aug 25 2001 - 10:10:58 CDT Quick temporary fix for OWA DOS Source: CCN Type: BID-3223 Microsoft Outlook Web Access Denial of Service Vulnerability Source: XF Type: UNKNOWN exchange-owa-dos(7039) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |