VulnerabilityModified
CVE-2018-16793
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
HIGH 8.6EPSS 11.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
- CVSS 3.0
- 8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 11.33% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- microsoft/exchange server
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/149411/Rollup-18-For-Microsoft-Exchange-Server-2010-SP3-Server-Side-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Sep/20Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105386Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2018/Sep/38Exploit, Issue Tracking, Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/149411/Rollup-18-For-Microsoft-Exchange-Server-2010-SP3-Server-Side-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Sep/20Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105386Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2018/Sep/38Exploit, Issue Tracking, Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.