CVE-2022-24405: Command Injection
Published Jul 27, 2022
·Updated
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.6
Event History
Jul 27, 2022
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
Description
Frequently Asked Questions
1
What is CVE-2022-24405?
CVE-2022-24405 is a vulnerability that allows OS Command Injection via a serialized Java class to the Documentconverter API in OX App Suite through version 7.10.6.
2
How severe is CVE-2022-24405?
CVE-2022-24405 has a severity rating of 9.8 on a scale of 1 to 10, with 10 being the most severe.
3
What software is affected by CVE-2022-24405?
OX App Suite through version 7.10.6 is affected by CVE-2022-24405.
4
How can I fix CVE-2022-24405?
To fix CVE-2022-24405, update OX App Suite to a version beyond 7.10.6.
5
Where can I find more information about CVE-2022-24405?
You can find more information about CVE-2022-24405 on the Open-Xchange website and the Seclists.org disclosure.