Overview
Some versions of Outlook Web Access (OWA) may use the no-cache instead of the no-store HTTP 1.1 directive. This results in web browsers caching sensitive information.
Description
Some versions of Outlook Web Access may use the Cache-Control: no-cache HTTP 1.1 directive. From RFC 2616: |
Impact
Sensitive information that is viewed during an Outlook Web Access session may be stored to disk. |
Solution
We are unware of a solution for this problem. |
Clear browser caches
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.9.2
- http://support.mozilla.com/en-US/kb/Options+window#Private_Data
- http://docs.info.apple.com/article.html?path=Safari/3.0/en/9300.html
- http://www.opera.com/support/tutorials/security/shared/
- http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software
- http://www.youtube.com/watch?v=e5rwtK5jwwk
- http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/8f451cda-67a3-4465-8e61-280541ee4c2b
Acknowledgements
Thanks to Bill Knox from MITRE reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 0.11 |
Date Public: | 2008-05-09 |
Date First Published: | 2008-05-09 |
Date Last Updated: | 2009-12-28 18:48 UTC |
Document Revision: | 28 |