Lucene search

K
nvd[email protected]NVD:CVE-2003-0904
HistoryJan 20, 2004 - 5:00 a.m.

CVE-2003-0904

2004-01-2005:00:00
CWE-200
web.nvd.nist.gov
8

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.005

Percentile

77.0%

Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.

Affected configurations

Nvd
Node
microsoftexchange_serverMatch2003-
OR
microsoftsharepoint_servicesMatch2.0
Node
microsoftwindows_server_2003enterprisex64
OR
microsoftwindows_server_2003Match-datacenterx64
OR
microsoftwindows_server_2003Match-standardx64
OR
microsoftwindows_server_2003Match-web
OR
microsoftwindows_server_2003Matchr2x64
VendorProductVersionCPE
microsoftexchange_server2003cpe:2.3:a:microsoft:exchange_server:2003:-:*:*:*:*:*:*
microsoftsharepoint_services2.0cpe:2.3:a:microsoft:sharepoint_services:2.0:*:*:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:enterprise:*:x64:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:datacenter:*:x64:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:standard:*:x64:*
microsoftwindows_server_2003-cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:web:*:*:*
microsoftwindows_server_2003r2cpe:2.3:o:microsoft:windows_server_2003:r2:*:*:*:*:*:x64:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.005

Percentile

77.0%

Related for NVD:CVE-2003-0904