PT-2002-1558 · Rsa+1 · Rsa Securid+1

Published

2002-06-11

·

Updated

2020-04-02

·

CVE-2002-0507

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook Web Access (OWA) (affected versions not specified)
Description The issue arises from an interaction between Microsoft Outlook Web Access (OWA) and RSA SecurID, allowing local users to bypass SecurID authentication for a previous user. This is achieved by submitting several OWA Authentication requests with the proper OWA password for the previous user, which is eventually accepted by OWA.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-0507

Affected Products

Outlook Web Access
Rsa Securid