CVE-2018-8153

CWE-2904 documents4 sources
Severity
5.4MEDIUM
EPSS
1.5%
top 19.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 13

Description

A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5microsoft/microsoft_exchange_server2016 Cumulative Update 8, 2016 Cumulative Update 9+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w3vw-mgpx-6mjp: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Excha2022-05-13
CVEList
CVE-2018-8153: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Excha2018-05-09

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Spoofing Vulnerability2018-05-08
CVE-2018-8153 (MEDIUM CVSS 5.4) | A spoofing vulnerability exists in | cvebase.io