This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2014-12-10
Product Exchange Server Last view 2019-07-15
Version 2013 Type Application
Update sp1  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:microsoft:exchange_server

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.4 2019-07-15 CVE-2019-1137

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

9.8 2018-05-09 CVE-2018-8154

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.

4.3 2018-05-09 CVE-2018-8151

An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154.

6.5 2018-03-14 CVE-2018-0940

Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allows an elevation of privilege vulnerability due to how links in the body of an email message are rewritten, aka "Microsoft Exchange Elevation of Privilege Vulnerability".

6.5 2018-03-14 CVE-2018-0924

Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.

5.3 2017-09-12 CVE-2017-11761

Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"

6.1 2017-07-11 CVE-2017-8621

Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".

6.1 2017-07-11 CVE-2017-8560

Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.

6.1 2017-07-11 CVE-2017-8559

Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8560.

6.1 2017-03-16 CVE-2017-0110

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."

7.4 2016-09-14 CVE-2016-3378

Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."

4.3 2016-09-14 CVE-2016-0138

Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information Disclosure Vulnerability."

6.1 2016-01-13 CVE-2016-0032

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."

6.1 2016-01-13 CVE-2016-0030

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."

4.3 2015-09-08 CVE-2015-2544

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability."

5 2015-09-08 CVE-2015-2505

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability."

4.3 2015-06-09 CVE-2015-2359

Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Exchange HTML Injection Vulnerability."

6.8 2015-06-09 CVE-2015-1771

Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."

4.3 2015-06-09 CVE-2015-1764

The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) issue, aka "Exchange Server-Side Request Forgery Vulnerability."

4.3 2015-03-11 CVE-2015-1632

Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."

5 2015-03-11 CVE-2015-1631

Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."

4.3 2015-03-11 CVE-2015-1630

Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Audit Report Cross Site Scripting Vulnerability."

4.3 2015-03-11 CVE-2015-1629

Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "ExchangeDLP Cross Site Scripting Vulnerability."

4.3 2015-03-11 CVE-2015-1628

Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted X-OWA-Canary cookie in an AD.RecipientType.User action, aka "OWA Modified Canary Parameter Cross Site Scripting Vulnerability."

3.5 2014-12-10 CVE-2014-6336

Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."

CWE : Common Weakness Enumeration

%idName
51% (14) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
18% (5) CWE-200 Information Exposure
7% (2) CWE-284 Access Control (Authorization) Issues
7% (2) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
7% (2) CWE-20 Improper Input Validation
3% (1) CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
3% (1) CWE-352 Cross-Site Request Forgery (CSRF)

Information Assurance Vulnerability Management (IAVM)

id Description
2015-B-0109 Multiple Vulnerabilities in Microsoft Exchange Server (MS15-103)
Severity: Category II - VMSKEY: V0061367
2015-A-0049 Multiple Vulnerabilities in Microsoft Exchange Server (MS15-026)
Severity: Category II - VMSKEY: V0058991
2014-A-0186 Multiple Vulnerabilities in Microsoft Exchange Server (MS14-075)
Severity: Category II - VMSKEY: V0057713

Snort® IPS/IDS

Date Description
2015-04-14 Microsoft Exchange UM Management user stored XSS attempt
RuleID : 33811 - Type : SERVER-MAIL - Revision : 3
2015-04-14 Microsoft Exchange Server custom DLP policy name cross-site scripting attempt
RuleID : 33810 - Type : SERVER-OTHER - Revision : 3
2015-04-14 Microsoft Exchange OWA X-OWA-CANARY command injection attempt
RuleID : 33807 - Type : SERVER-MAIL - Revision : 3
2015-04-14 Microsoft Outlook WebAccess msgParam cross site scripting attempt
RuleID : 33762 - Type : SERVER-WEBAPP - Revision : 3
2015-01-08 Microsoft Exchange OWA meeting invite XSS attempt
RuleID : 32705 - Type : SERVER-MAIL - Revision : 2
2015-01-08 Microsoft Outlook Web Access parameter cross site scripting attempt
RuleID : 32682 - Type : SERVER-WEBAPP - Revision : 3
2015-01-08 Microsoft Outlook Web Access parameter cross site scripting attempt
RuleID : 32681 - Type : SERVER-WEBAPP - Revision : 3

Nessus® Vulnerability Scanner

id Description
2017-09-12 Name: The Microsoft Exchange Server installed on the remote host is affected by mul...
File: smb_nt_ms17_sep_exchange.nasl - Type: ACT_GATHER_INFO
2017-07-13 Name: The remote Microsoft Exchange Server is affected by multiple vulnerabilities.
File: smb_nt_ms17_jul_4018588.nasl - Type: ACT_GATHER_INFO
2017-03-15 Name: The remote Microsoft Exchange Server is affected by multiple vulnerabilities.
File: smb_nt_ms17-015.nasl - Type: ACT_GATHER_INFO
2016-09-13 Name: The remote Microsoft Exchange Server is affected by multiple vulnerabilities.
File: smb_nt_ms16-108.nasl - Type: ACT_GATHER_INFO
2016-01-13 Name: The remote Microsoft Exchange server is affected by multiple spoofing vulnera...
File: smb_nt_ms16-010.nasl - Type: ACT_GATHER_INFO
2015-09-10 Name: The remote Microsoft Exchange server is affected by multiple information disc...
File: smb_nt_ms15-103.nasl - Type: ACT_GATHER_INFO
2015-06-10 Name: The remote Microsoft Exchange server is affected by multiple vulnerabilities.
File: smb_nt_ms15-064.nasl - Type: ACT_GATHER_INFO
2015-03-10 Name: The remote Microsoft Exchange server is affected by multiple vulnerabilities.
File: smb_nt_ms15-026.nasl - Type: ACT_GATHER_INFO
2014-12-09 Name: The remote mail server is affected by multiple vulnerabilities.
File: smb_nt_ms14-075.nasl - Type: ACT_GATHER_INFO