MajorExchange 2003 Outlook Web Access Major Security Issue
Last night we discovered that once a user logs in and accesses ther Exchange account through Outlook Web Access that they can access any other account without re-authenticating by simply changing the last part of the URL in their browser to another user. When doing so and pressing enter the user will then has full access to that other users account without re-authenticating. We are running Exchange Server 2003 SP2 (Standard) on a MS Server 2003 Box Has anyone seen this before? If so what is the solution. Jeff
March 11th, 2010 12:35am

On Wed, 10 Mar 2010 21:35:02 +0000, seekatzj wrote:>Last night we discovered that once a user logs in and accesses ther Exchange account through Outlook Web Access that they can access any other account without re-authenticating by simply changing the last part of the URL in their browser to another user. When doing so and pressing enter the user will then has full access to that other users account without re-authenticating. We are running Exchange Server 2003 SP2 (Standard) on a MS Server 2003 Box Has anyone seen this before? If so what is the solution. Jeff Verify that you haven't given "Receive As" permission to a group like"Everyone".---Rich MatheisenMCSE+I, Exchange MVP--- Rich Matheisen MCSE+I, Exchange MVP
Free Windows Admin Tool Kit Click here and download it now
March 11th, 2010 4:24am

On Wed, 10 Mar 2010 21:35:02 +0000, seekatzj wrote:>Last night we discovered that once a user logs in and accesses ther Exchange account through Outlook Web Access that they can access any other account without re-authenticating by simply changing the last part of the URL in their browser to another user. When doing so and pressing enter the user will then has full access to that other users account without re-authenticating. We are running Exchange Server 2003 SP2 (Standard) on a MS Server 2003 Box Has anyone seen this before? If so what is the solution. Jeff ---Rich MatheisenMCSE+I, Exchange MVP--- Rich Matheisen MCSE+I, Exchange MVP
March 11th, 2010 6:05am

Hi,How about your question? Any updates?Agree with Rich, it regards mailbox permission.If the user can open the mailbox in the same mailbox store, you need to check the perssion in ESM->administrator group->first administrator group->server->server name->storage group->mailbox store's properties->security tabSame for storage group, server, AG and organization.Frank Wang
Free Windows Admin Tool Kit Click here and download it now
March 12th, 2010 10:49am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics