Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
ID: b55cec22-53dd-5361-9962-0eb122eba2ef
STIX ID: report--b55cec22-53dd-5361-9962-0eb122eba2ef
Feed Name: Zero Day Initiative (ZDI) Blog
This report discusses Server Side Request Forgery (SSRF) as a web application vulnerability, describing categories for evaluating SSRF findings: internal vs. external application, exposure of loopback services, privileges required, and what can be achieved (request shaping and response handling). It emphasizes that SSRF impact depends on context—especially whether responses are returned and what protocols and request controls are available—and that vendor assessments may differ from attacker evaluations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
