CVE-2020-12645: Input Validation
Published Aug 31, 2020
·Updated
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite>=7.10.1<=7.10.3
Event History
Aug 31, 2020
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12645?
The severity of CVE-2020-12645 is classified as critical with a CVSS score of 9.8.
2
Which version of OX App Suite is affected by CVE-2020-12645?
OX App Suite versions 7.10.1 to 7.10.3 are affected by CVE-2020-12645.
3
What are the impacts of CVE-2020-12645?
CVE-2020-12645 can lead to improper input validation for rate limits, spoofed vacation notices, and excessive memory consumption in /apps/load.
4
How can I mitigate CVE-2020-12645?
To mitigate CVE-2020-12645, it is recommended to update OX App Suite to a version beyond 7.10.3.
5
Where can I find more information about CVE-2020-12645?
More information about CVE-2020-12645 can be found at the following references: [1] [2].