PT-2015-4228 · Open Xchange · Open-Xchange Server+1

Published

2015-02-17

·

Updated

2018-10-09

·

CVE-2014-9466

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open-Xchange (OX) AppSuite and Server versions prior to 7.4.2-rev42 Open-Xchange (OX) AppSuite and Server version 7.6.0 prior to 7.6.0-rev36 Open-Xchange (OX) AppSuite and Server version 7.6.1 prior to 7.6.1-rev14
Description The issue is related to improper handling of directory permissions, allowing remote authenticated users to read files via unspecified vectors. This is related to the folder identifier.
Recommendations For versions prior to 7.4.2-rev42, update to version 7.4.2-rev42 or later. For version 7.6.0 prior to 7.6.0-rev36, update to version 7.6.0-rev36 or later. For version 7.6.1 prior to 7.6.1-rev14, update to version 7.6.1-rev14 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9466

Affected Products

Open-Xchange Appsuite
Open-Xchange Server