Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
BID:9118
Info
Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
| Bugtraq ID: | 9118 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0904 CVE-1999-0386 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 27 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
Microsoft Windows SharePoint Services 2.0 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Exchange Server 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
It has been reported that Microsoft Exchange Server 2003 may be prone to a weakness when Microsoft Windows SharePoint Services 2.0 is installed on a machine running both Exchange Server 2003 and Microsoft Windows Server 2003. This installation may cause the Kerberos authentication employed by the server to be disabled in IIS (Internet Information Services) resorting to NTLM.
It has been reported that Microsoft Exchange Server 2003 may be prone to a weakness when Microsoft Windows SharePoint Services 2.0 is installed on a machine running both Exchange Server 2003 and Microsoft Windows Server 2003. This installation may cause the Kerberos authentication employed by the server to be disabled in IIS (Internet Information Services) resorting to NTLM.
Exploit / POC
Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
References:
References:
- Exchange 2003 and Outlook Web Access Issue (Microsoft)