CVE-2003-0904

Severity
6.0MEDIUM
EPSS
14.2%
top 5.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateApr 29

Description

Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wpp8-hx5r-4jfx: Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can2022-04-29
CVEList
CVE-2003-0904: Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can2004-01-08
CVE-2003-0904 (MEDIUM CVSS 6) | Microsoft Exchange 2003 and Outlook | cvebase.io