← Back

CVE-2019-1137

nvd nist
Published: Jul 15, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

Affected (41)

1 product
Exchange Server
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2013
Version 2013 cumulative_update_10
Version 2013 cumulative_update_11
Version 2013 cumulative_update_12
Version 2013 cumulative_update_13
Version 2013 cumulative_update_14
Version 2013 cumulative_update_15
Version 2013 cumulative_update_16
Version 2013 cumulative_update_17
Version 2013 cumulative_update_18
Version 2013 cumulative_update_19
Version 2013 cumulative_update_1
Version 2013 cumulative_update_20
Version 2013 cumulative_update_21
Version 2013 cumulative_update_22
Version 2013 cumulative_update_23
Version 2013 cumulative_update_2
Version 2013 cumulative_update_3
Version 2013 cumulative_update_5
Version 2013 cumulative_update_6
Version 2013 cumulative_update_7
Version 2013 cumulative_update_8
Version 2013 cumulative_update_9
Version 2013 sp1
Configuration B
14 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2016
Version 2016 cumulative_update_10
Version 2016 cumulative_update_11
Version 2016 cumulative_update_12
Version 2016 cumulative_update_13
Version 2016 cumulative_update_1
Version 2016 cumulative_update_2
Version 2016 cumulative_update_3
Version 2016 cumulative_update_4
Version 2016 cumulative_update_5
Version 2016 cumulative_update_6
Version 2016 cumulative_update_7
Version 2016 cumulative_update_8
Version 2016 cumulative_update_9
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2019
Version 2019 cumulative_update_1
Version 2019 cumulative_update_2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.