CVE-2019-1137

Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka Microsoft Exchange Server Spoofing Vulnerability.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.671

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2013 CU23 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2016 CU12 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2016 CU13 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2019 CU2 (KB4509408)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2019 CU1 (KB4509408)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-27157Security Update For Exchange Server 2013 CU23 (KB4509409)
PATCH-27158Security Update For Exchange Server 2016 CU12 (KB4509409)
PATCH-27159Security Update For Exchange Server 2016 CU13 (KB4509409)
PATCH-27160Security Update For Exchange Server 2019 CU2 (KB4509408)
PATCH-27161Security Update For Exchange Server 2019 CU1 (KB4509408)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234