First published: Tue Jan 14 2020(Updated: )
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Open-xchange Appsuite | <=7.4.1 | |
Open-xchange Open-xchange Appsuite | =7.4.2 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision1 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision10 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision2 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision3 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision4 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision5 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision6 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision7 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision8 | |
Open-xchange Open-xchange Appsuite | =7.4.2-revision9 | |
Open-xchange Open-xchange Appsuite | =7.6.0 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision1 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision2 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision3 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision4 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision5 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision6 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision7 | |
Open-xchange Open-xchange Appsuite | =7.6.0-revision8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2014-5238.
The severity of CVE-2014-5238 is high (7.8).
The affected software of CVE-2014-5238 is Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9.
CVE-2014-5238 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
Yes, there are references available for CVE-2014-5238. You can find them at the following links: [Link 1](http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html), [Link 2](http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf), [Link 3](http://www.securityfocus.com/archive/1/archive/1/533443/100/0/threaded).