Vulnerability Name:

CVE-2002-0507 (CCN-8681)

Assigned:2002-03-28
Published:2002-03-28
Updated:2020-04-02
Summary:An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Thu Mar 28 2002 - 03:58:58 CST
Authentication with RSA SecurID and Outlook web access

Source: MITRE
Type: CNA
CVE-2002-0507

Source: BUGTRAQ
Type: Third Party Advisory, VDB Entry, Vendor Advisory
20020328 Authentication with RSA SecurID and Outlook web access

Source: XF
Type: Vendor Advisory
exchange-owa-securid-bypass(8681)

Source: CCN
Type: OSVDB ID: 4932
Microsoft Outlook Web Access SecurID Authentication Bypass

Source: BID
Type: Third Party Advisory, VDB Entry, Vendor Advisory
4390

Source: CCN
Type: BID-4390
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability

Source: XF
Type: UNKNOWN
exchange-owa-securid-bypass(8681)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/h:rsa:securid:5.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:exchange_server:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:rsa:securid_web_agent:5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft exchange server 5.5 -
    microsoft exchange server 5.5 sp1
    microsoft exchange server 5.5 sp2
    microsoft exchange server 5.5 sp3
    microsoft exchange server 5.5 sp4
    microsoft exchange server 2000 -
    microsoft exchange server 2000 sp1
    microsoft exchange server 2000 sp2
    rsa securid 5.0
    microsoft exchange server 5.5
    microsoft exchange server 2000
    rsa securid web agent 5