CVE-2014-9049: Infoleak
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9049?
CVE-2014-9049 has a moderate severity rating due to its potential to expose valid session IDs to remote authenticated users.
How do I fix CVE-2014-9049?
To fix CVE-2014-9049, upgrade ownCloud Server to version 6.0.6 or 7.0.3 or later, which includes the necessary security patches.
Who is affected by CVE-2014-9049?
Users of ownCloud Server versions 6.x prior to 6.0.6 and 7.x prior to 7.0.3 are affected by CVE-2014-9049.
What impact does CVE-2014-9049 have?
CVE-2014-9049 can allow an attacker with authenticated access to retrieve all valid session IDs, potentially allowing unauthorized access to user sessions.
When was CVE-2014-9049 disclosed?
CVE-2014-9049 was disclosed in November 2014, and users were advised to take immediate action to secure their installations.