CVE-2002-0507

Microsoft Exchange Server - Authentication Bypass

Title source: rule

Description

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Scores

EPSS 0.0099
EPSS Percentile 76.6%

Classification

CWE
CWE-287
Status draft

Affected Products (9)

microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
rsa/securid

Timeline

Published Aug 12, 2002
Tracked Since Feb 18, 2026