Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026
CVE-2002-0507
CVE-2002-0507
Description
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
Affected products
9cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2000:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- online.securityfocus.com/archive/1/264705nvdThird Party AdvisoryVDB EntryVendor Advisory
- www.iss.net/security_center/static/8681.phpnvdVendor Advisory
- www.securityfocus.com/bid/4390nvdThird Party AdvisoryVDB EntryVendor Advisory
News mentions
0No linked articles in our index yet.