CVE-2021-33493: Code Injection
Published Nov 22, 2021
·Updated
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:24 AM
Data Sourced
via MITRE·08:24 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33493.
2
What is the severity of CVE-2021-33493?
The severity of CVE-2021-33493 is medium.
3
What is the affected software by CVE-2021-33493?
The affected software by CVE-2021-33493 is Open-xchange Ox App Suite version up to and including 7.10.5.
4
How can Code Injection occur in this vulnerability?
Code Injection can occur in this vulnerability by using Java classes in a YAML format.
5
Are there any references available for CVE-2021-33493?
Yes, you can find references for CVE-2021-33493 at the following links: [Reference 1](http://packetstormsecurity.com/files/165028/OX-App-Suite-Ox-Documents-7.10.x-XSS-Code-Injection-Traversal.html), [Reference 2](https://open-xchange.com), [Reference 3](https://seclists.org/fulldisclosure/2021/Nov/42).