CVE-2020-15003: Medium severity open-xchange app suite backend vulnerability
Published Oct 23, 2020
·Updated
OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
Affected Software
2 affected components
Open-Xchange Open-Xchange AppSuite=7.10.2
Open-Xchange Open-Xchange AppSuite=7.10.3
Event History
Oct 23, 2020
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
Description
Frequently Asked Questions
1
What is CVE-2020-15003?
CVE-2020-15003 is a vulnerability in OX App Suite through version 7.10.3 that allows information exposure.
2
How does CVE-2020-15003 work?
CVE-2020-15003 allows a user to obtain the IP address and User-Agent string of a different user.
3
What is the severity of CVE-2020-15003?
CVE-2020-15003 has a severity score of 4.3, which is considered medium.
4
What software is affected by CVE-2020-15003?
OX App Suite versions 7.10.2 and 7.10.3 are affected by CVE-2020-15003.
5
How can I fix CVE-2020-15003?
To fix CVE-2020-15003, update OX App Suite to version 7.10.4 or higher.