CVE-2010-2091

UnknownEPSS 17.94%

Last modified

CVE-2010-2091 is a vulnerability of currently unknown severity. Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.. EPSS estimates a 17.94% chance of exploitation in the next 30 days.

Description

Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.

Metrics

EPSS Probability
17.94%

96.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MicrosoftExchange Server2007Sp2 Update Rollup 4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-2091?
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
How severe is CVE-2010-2091?
Severity scoring for CVE-2010-2091 is pending analysis. The EPSS model estimates a 17.94% probability of exploitation in the next 30 days.
How do I fix CVE-2010-2091?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-2091?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST