CVE-2014-9049 — Sensitive Information Exposure in Server
Severity
4.0MEDIUMNVD
EPSS
0.2%
top 60.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateMay 17
Description
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9