Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2019-0588

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.

  • Published: Jan 8, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-0588
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 4
  • AV:N/AC:L/Au:S/C:P/I:N/A:N

CWEs:

Software From Fixed in
microsoft / exchange_server 2013-cumulative_update_21 2013-cumulative_update_21.x
microsoft / exchange_server 2016-cumulative_update_10 2016-cumulative_update_10.x
microsoft / exchange_server 2016-cumulative_update_11 2016-cumulative_update_11.x
microsoft / exchange_server 2010-sp3_rollup25 2010-sp3_rollup25.x
microsoft / exchange_server 2019 2019.x