cbcvebase.
CVE-2014-9466
published 2015-02-17

CVE-2014-9466: Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory…

PriorityP420medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.13%
79.7th percentile
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."

Affected

3 ranges
VendorProductVersion rangeFixed in
open-xchangeopen-xchange_appsuite
open-xchangeopen-xchange_appsuite
open-xchangeopen-xchange_appsuite
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.