VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026

CVE-2002-0507

CVE-2002-0507

Description

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Affected products

9
  • cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2000:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:*
  • cpe:2.3:h:rsa:securid:5.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.