CVE-2014-9049Sensitive Information Exposure in Server

Severity
4.0MEDIUMNVD
EPSS
0.2%
top 60.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateMay 17

Description

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

NVDowncloud/owncloud_server9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-255j-gp8h-r5hh: The documents application in ownCloud Server 62022-05-17
CVEList
CVE-2014-9049: The documents application in ownCloud Server 62015-02-04
CVE-2014-9049 — Sensitive Information Exposure | cvebase