← Back

CVE-2014-5238

nvd nist
Published: Jan 14, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.

Affected (21)

1 product
Open Xchange Appsuite
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Up to 7.4.1
Version 7.4.2
Version 7.4.2 revision10
Version 7.4.2 revision1
Version 7.4.2 revision2
Version 7.4.2 revision3
Version 7.4.2 revision4
Version 7.4.2 revision5
Version 7.4.2 revision6
Version 7.4.2 revision7
Version 7.4.2 revision8
Version 7.4.2 revision9
Version 7.6.0
Version 7.6.0 revision1
Version 7.6.0 revision2
Version 7.6.0 revision3
Version 7.6.0 revision4
Version 7.6.0 revision5
Version 7.6.0 revision6
Version 7.6.0 revision7
Version 7.6.0 revision8

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.