First published: Thu Sep 05 2013(Updated: )
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | =6.22.0 | |
Open-Xchange App Suite Backend | =6.22.1 | |
Open-Xchange App Suite Backend | =7.0.1 | |
Open-Xchange App Suite Backend | =7.0.2 | |
SUSE Linux Openexchange Server | =6.22.0 | |
SUSE Linux Openexchange Server | =6.22.1 | |
SUSE Linux Openexchange Server | =7.0.1 | |
SUSE Linux Openexchange Server | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2582 is classified as a medium severity vulnerability due to the potential for open redirect attacks.
To fix CVE-2013-2582, upgrade Open-Xchange AppSuite or Server to version 6.22.0 rev15, 6.22.1 rev17, 7.0.1 rev6, or 7.0.2 rev7 or later.
CVE-2013-2582 can be exploited to conduct arbitrary HTTP header injection and open redirect attacks.
CVE-2013-2582 affects Open-Xchange AppSuite and Server versions earlier than 6.22.0 rev15, 6.22.1 rev17, 7.0.1 rev6, and 7.0.2 rev7.
Organizations using vulnerable versions of Open-Xchange AppSuite or Server are at risk of attack due to CVE-2013-2582.