PT-2015-4228 · Open Xchange · Open-Xchange Server+1
Published
2015-02-17
·
Updated
2018-10-09
·
CVE-2014-9466
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open-Xchange (OX) AppSuite and Server versions prior to 7.4.2-rev42
Open-Xchange (OX) AppSuite and Server version 7.6.0 prior to 7.6.0-rev36
Open-Xchange (OX) AppSuite and Server version 7.6.1 prior to 7.6.1-rev14
Description
The issue is related to improper handling of directory permissions, allowing remote authenticated users to read files via unspecified vectors. This is related to the
folder identifier.Recommendations
For versions prior to 7.4.2-rev42, update to version 7.4.2-rev42 or later.
For version 7.6.0 prior to 7.6.0-rev36, update to version 7.6.0-rev36 or later.
For version 7.6.1 prior to 7.6.1-rev14, update to version 7.6.1-rev14 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Xchange Appsuite
Open-Xchange Server