PT-2016-1040 · Microsoft · Outlook Web Access+1

Publicado

2016-01-12

·

Atualizado

2020-04-09

·

CVE-2016-0030

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions 2013 PS1 through 2013 Cumulative Update 10 Microsoft Exchange Server version 2016
Description A cross-site scripting (XSS) issue exists due to inadequate protection of the web page structure in Outlook Web Access (OWA), allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. This can lead to script or content injection attacks, where an attacker could trick the user into disclosing sensitive information or redirect the user to a malicious website.
Recommendations For Microsoft Exchange Server versions 2013 PS1 through 2013 Cumulative Update 10, update to a version that includes the fix for this issue. For Microsoft Exchange Server version 2016, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the OWA component to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00107
CVE-2016-0030

Produtos afetados

Exchange Server
Outlook Web Access