Open-Xchange Ox App Suite vulnerabilities
48 known vulnerabilities affecting open-xchange/ox_app_suite.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM42
Vulnerabilities
Page 3 of 3
CVE-2023-24599P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-05-29
CVE-2023-24599 [MEDIUM] CWE-843 CVE-2023-24599: OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of ar
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
nvd
CVE-2023-24600P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-05-29
CVE-2023-24600 [MEDIUM] CWE-863 CVE-2023-24600: OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for r
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
nvd
CVE-2021-38378P4MEDIUMCVSS 4.3≤ 7.10.52021-11-22
CVE-2021-38378 [MEDIUM] CVE-2021-38378: OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
nvd
CVE-2023-24604P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-05-29
CVE-2023-24604 [MEDIUM] CVE-2023-24604: OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g.,
OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.
nvd
CVE-2022-43698P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43698 [MEDIUM] CWE-918 CVE-2022-43698: OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-lis
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
nvd
CVE-2022-43699P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-04-15
CVE-2022-43699 [MEDIUM] CWE-918 CVE-2022-43699: OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-li
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
nvd
CVE-2023-24598P4MEDIUMCVSS 4.3fixed in 7.10.6v7.10.62023-05-29
CVE-2023-24598 [MEDIUM] CWE-203 CVE-2023-24598: OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lis
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
nvd
CVE-2023-24605P4MEDIUMCVSS 4.2fixed in 7.10.6v7.10.62023-05-29
CVE-2023-24605 [MEDIUM] CWE-862 CVE-2023-24605: OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from
OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading contact data, and renaming tokens.
nvd
← Previous3 / 3