{"api_version":"1","generated_at":"2026-07-23T09:38:51+00:00","cve":"CVE-2013-2308","urls":{"html":"https://cve.report/CVE-2013-2308","api":"https://cve.report/api/cve/CVE-2013-2308.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-2308","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-2308"},"summary":{"title":"CVE-2013-2308","description":"The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors.","state":"PUBLISHED","assigner":"jpcert","published_at":"2013-05-09 12:31:19","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.softbanktech.jp/news/20121029.html","name":"https://www.softbanktech.jp/news/20121029.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ニュース | SBテクノロジー (SBT)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2013-000035","name":"http://jvndb.jvn.jp/jvndb/JVNDB-2013-000035","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://jvn.jp/en/jp/JVN61972596/index.html","name":"http://jvn.jp/en/jp/JVN61972596/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#61972596: Online Service Gate vulnerable in Office 365 password management","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-2308","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2308","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"2308","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"softbanktech","cpe5":"online_service_gate","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T15:36:46.360Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.softbanktech.jp/news/20121029.html"},{"name":"JVNDB-2013-000035","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2013-000035"},{"name":"JVN#61972596","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN61972596/index.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-05-09T10:00:00.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.softbanktech.jp/news/20121029.html"},{"name":"JVNDB-2013-000035","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2013-000035"},{"name":"JVN#61972596","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN61972596/index.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2013-2308","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.softbanktech.jp/news/20121029.html","refsource":"CONFIRM","url":"https://www.softbanktech.jp/news/20121029.html"},{"name":"JVNDB-2013-000035","refsource":"JVNDB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2013-000035"},{"name":"JVN#61972596","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN61972596/index.html"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2013-2308","datePublished":"2013-05-09T10:00:00.000Z","dateReserved":"2013-03-04T00:00:00.000Z","dateUpdated":"2024-09-17T00:30:48.208Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-05-09 12:31:19","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:softbanktech:online_service_gate:-:*:*:*:*:*:*:*","matchCriteriaId":"E7CAE2E8-4707-4C3B-9680-315ACC651652"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"2308","Ordinal":"1","Title":"CVE-2013-2308","CVE":"CVE-2013-2308","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"2308","Ordinal":"1","NoteData":"The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors.","Type":"Description","Title":"CVE-2013-2308"},{"CveYear":"2013","CveId":"2308","Ordinal":"2","NoteData":"2013-05-09","Type":"Other","Title":"Published"}]}}}