Microsoft Exchange OWA Global Address List Disclosure Vulnerability
BID:3301
Info
Microsoft Exchange OWA Global Address List Disclosure Vulnerability
| Bugtraq ID: | 3301 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2001 12:00AM |
| Updated: | Sep 06 2001 12:00AM |
| Credit: | Discovered by Noam Rathaus of SecuriTeam.com and published in a Microsoft Security Bulletin MS01-047 on Sep 6, 2001. |
| Vulnerable: |
Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Exploit / POC
Microsoft Exchange OWA Global Address List Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Exchange OWA Global Address List Disclosure Vulnerability
Solution:
Microsoft has released a patch which rectifies this issue (note that Exchange Service Pack 4 must be installed before applying this patch):
Microsoft Exchange Server 5.5 SP4
Solution:
Microsoft has released a patch which rectifies this issue (note that Exchange Service Pack 4 must be installed before applying this patch):
Microsoft Exchange Server 5.5 SP4
References
Microsoft Exchange OWA Global Address List Disclosure Vulnerability
References:
References:
- Exchange Public Folders Information Leakage (SecuriTeam.com)
- Microsoft Security Bulletin MS01-047 (Microsoft)