Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
BID:4390
Info
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
| Bugtraq ID: | 4390 |
| Class: | Environment Error |
| CVE: |
CVE-2002-0507 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Jun 05 2019 11:00AM |
| Credit: | Discovered by Marzio Scalise <[email protected]>. |
| Vulnerable: |
Rsa SecurID 5.0 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
RSA SecurID is a two factor Authentication system, designed to allow remote authentication to a variety of resources through the usage of an authenticator in conjunction with a user password. Microsoft Outlook Web Access (OWA) is a component of Microsoft Exchange Server, used to provide a web interface for email.
Reportedly, a user able to access the OWA system after proper SecurID authentication may then attempt to access OWA as a different user without providing additional SecurID authentication. A valid user and password is still required for both OWA authentication attempts.
Although an error message is displayed, multiple attempts will reportedly result in access to the OWA system.
RSA SecurID is a two factor Authentication system, designed to allow remote authentication to a variety of resources through the usage of an authenticator in conjunction with a user password. Microsoft Outlook Web Access (OWA) is a component of Microsoft Exchange Server, used to provide a web interface for email.
Reportedly, a user able to access the OWA system after proper SecurID authentication may then attempt to access OWA as a different user without providing additional SecurID authentication. A valid user and password is still required for both OWA authentication attempts.
Although an error message is displayed, multiple attempts will reportedly result in access to the OWA system.
Exploit / POC
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
References:
References:
- Exchange Server Home Page (Microsoft)
- SecurID Product Homepage (RSA Security)