|
|

CVE Reference: CVE-2003-0904 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2003-0904 |
|
|
Description: Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/13869 SAID Secunia Advisory: SA10615 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:477 NTBUGTRAQ http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0311&L=ntbugtraq&F=P&S=&P=9281 MS http://www.microsoft.com/technet/security/bulletin/ms04-002.asp CONFIRM http://www.microsoft.com/exchange/support/e2k3owa.asp CERT-VN 530660 BID 9118 9409 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |