Deeply-nested OWA Request Can Consume Server CPU Availabilit
A security vulnerability exists in Exchange 2000 Outlook Web Access, because it will accept and process a request for an item in an authenticated user´s mailbox without verifying first that the folder structure is valid.
A security vulnerability exists in Exchange 2000 Outlook Web Access, because it will accept and process a request for an item in an authenticated user´s mailbox without verifying first that the folder structure is valid. An attacker could mount a denial of service attack by repeatedly levying a request for a non-existent but deeply nested folder in his own mailbox.
Read more
Read more
Participate on our website and join the conversation
This topic is archived. New comments cannot be posted and votes cannot be cast.