Vulnerability CVE-2014-9466


Published: 2015-02-17

Description:
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Open-Xchange Server 6 / OX AppSuite 7.6.1 Exposure
Martin Heiland
13.02.2015

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Open-xchange -> Open-xchange appsuite 

 References:
http://packetstormsecurity.com/files/130379/Open-Xchange-Server-6-OX-AppSuite-7.6.1-Exposure.html
http://www.securityfocus.com/archive/1/534695/100/0/threaded
http://www.securityfocus.com/bid/72587
http://www.securitytracker.com/id/1031744
https://exchange.xforce.ibmcloud.com/vulnerabilities/100867

Copyright 2024, cxsecurity.com

 

Back to Top