PT-2018-13753 · Microsoft · Exchange Server

Alphan Yavas

·

Publicado

2018-09-21

·

Atualizado

2018-11-20

·

CVE-2018-16793

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions prior to Rollup 18 for Microsoft Exchange Server 2010 SP3
Description The issue concerns a Server-Side Request Forgery (SSRF) vulnerability. It can be exploited via the username parameter in the "/owa/auth/logon.aspx" API endpoint, which is part of the OWA (Outlook Web Access) login page.
Recommendations For versions prior to Rollup 18 for Microsoft Exchange Server 2010 SP3, apply Rollup 18 to resolve the issue. As a temporary workaround, consider restricting access to the "/owa/auth/logon.aspx" API endpoint to minimize the risk of exploitation. Avoid using the username parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16793

Produtos afetados

Exchange Server