← Back

CVE-2018-5752

nvd nist
Published: Jun 16, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.

Affected (78)

1 product
Open Xchange Appsuite
Configuration A
78 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Up to 7.6.3
Version 7.6.3 rev14
Version 7.6.3 rev15
Version 7.6.3 rev16
Version 7.6.3 rev17
Version 7.6.3 rev18
Version 7.6.3 rev20
Version 7.6.3 rev22
Version 7.6.3 rev23
Version 7.6.3 rev24
Version 7.6.3 rev25
Version 7.6.3 rev26
Version 7.6.3 rev28
Version 7.6.3 rev29
Version 7.6.3 rev30
Version 7.6.3 rev31
Version 7.6.3 rev32
Version 7.6.3 rev33
Version 7.6.3 rev35
Version 7.8.0
Version 7.8.2
Version 7.8.3
Version 7.8.3 rev10
Version 7.8.3 rev11
Version 7.8.3 rev12
Version 7.8.3 rev13
Version 7.8.3 rev14
Version 7.8.3 rev15
Version 7.8.3 rev16
Version 7.8.3 rev17
Version 7.8.3 rev18
Version 7.8.3 rev19
Version 7.8.3 rev20
Version 7.8.3 rev21
Version 7.8.3 rev22
Version 7.8.3 rev23
Version 7.8.3 rev24
Version 7.8.3 rev25
Version 7.8.3 rev26
Version 7.8.3 rev27
Version 7.8.3 rev28
Version 7.8.3 rev29
Version 7.8.3 rev30
Version 7.8.3 rev31
Version 7.8.3 rev32
Version 7.8.3 rev33
Version 7.8.3 rev34
Version 7.8.3 rev35
Version 7.8.3 rev36
Version 7.8.3 rev38
Version 7.8.3 rev39
Version 7.8.3 rev40
Version 7.8.3 rev41
Version 7.8.3 rev42
Version 7.8.3 rev43
Version 7.8.3 rev5
Version 7.8.3 rev6
Version 7.8.3 rev8
Version 7.8.3 rev9
Version 7.8.4
Version 7.8.4 rev10
Version 7.8.4 rev11
Version 7.8.4 rev13
Version 7.8.4 rev14
Version 7.8.4 rev15
Version 7.8.4 rev16
Version 7.8.4 rev17
Version 7.8.4 rev18
Version 7.8.4 rev19
Version 7.8.4 rev20
Version 7.8.4 rev21
Version 7.8.4 rev3
Version 7.8.4 rev4
Version 7.8.4 rev5
Version 7.8.4 rev6
Version 7.8.4 rev7
Version 7.8.4 rev8
Version 7.8.4 rev9

References (6)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.