Lucene search

K
cveMitreCVE-2014-5237
HistoryDec 01, 2014 - 3:59 p.m.

CVE-2014-5237

2014-12-0115:59:04
mitre
web.nvd.nist.gov
24
ssrf
open-xchange
ox appsuite
vulnerability
remote attackers
arbitrary requests
embedded images
url
text document

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

48.9%

Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview.

Affected configurations

Nvd
Node
open-xchangeapp_suiteMatch7.4.2rev6
OR
open-xchangeapp_suiteMatch7.4.2rev7
OR
open-xchangeapp_suiteMatch7.4.2rev8
OR
open-xchangeapp_suiteMatch7.4.2rev9
OR
open-xchangeapp_suiteMatch7.6.0rev6
OR
open-xchangeapp_suiteMatch7.6.0rev7
OR
open-xchangeapp_suiteMatch7.6.0rev8
OR
open-xchangeapp_suiteMatch7.6.0rev9
VendorProductVersionCPE
open-xchangeapp_suite7.4.2cpe:2.3:a:open-xchange:app_suite:7.4.2:rev6:*:*:*:*:*:*
open-xchangeapp_suite7.4.2cpe:2.3:a:open-xchange:app_suite:7.4.2:rev7:*:*:*:*:*:*
open-xchangeapp_suite7.4.2cpe:2.3:a:open-xchange:app_suite:7.4.2:rev8:*:*:*:*:*:*
open-xchangeapp_suite7.4.2cpe:2.3:a:open-xchange:app_suite:7.4.2:rev9:*:*:*:*:*:*
open-xchangeapp_suite7.6.0cpe:2.3:a:open-xchange:app_suite:7.6.0:rev6:*:*:*:*:*:*
open-xchangeapp_suite7.6.0cpe:2.3:a:open-xchange:app_suite:7.6.0:rev7:*:*:*:*:*:*
open-xchangeapp_suite7.6.0cpe:2.3:a:open-xchange:app_suite:7.6.0:rev8:*:*:*:*:*:*
open-xchangeapp_suite7.6.0cpe:2.3:a:open-xchange:app_suite:7.6.0:rev9:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

48.9%