logo

Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments

ID: b55cec22-53dd-5361-9962-0eb122eba2ef

STIX ID: report--b55cec22-53dd-5361-9962-0eb122eba2ef

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
15/100

Date Published: 2023-11-02

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This report discusses Server Side Request Forgery (SSRF) as a web application vulnerability, describing categories for evaluating SSRF findings: internal vs. external application, exposure of loopback services, privileges required, and what can be achieved (request shaping and response handling). It emphasizes that SSRF impact depends on context—especially whether responses are returned and what protocols and request controls are available—and that vendor assessments may differ from attacker evaluations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.