← Back

CVE-2022-37313

nvd nist
Published: Dec 26, 2022Modified: Apr 14, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

Affected (53)

1 product
Open Xchange Appsuite
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Before 7.10.5
Version 7.10.5
Version 7.10.5 patch_release_5961
Version 7.10.5 patch_release_5973
Version 7.10.5 patch_release_5976
Version 7.10.5 patch_release_5982
Version 7.10.5 patch_release_5989
Version 7.10.5 patch_release_5994
Version 7.10.5 patch_release_6000
Version 7.10.5 patch_release_6003
Version 7.10.5 patch_release_6008
Version 7.10.5 patch_release_6010
Version 7.10.5 patch_release_6016
Version 7.10.5 patch_release_6020
Version 7.10.5 patch_release_6026
Version 7.10.5 patch_release_6029
Version 7.10.5 patch_release_6034
Version 7.10.5 patch_release_6035
Version 7.10.5 patch_release_6038
Version 7.10.5 patch_release_6046
Version 7.10.5 patch_release_6051
Version 7.10.5 patch_release_6053
Version 7.10.5 patch_release_6060
Version 7.10.5 patch_release_6061
Version 7.10.5 patch_release_6066
Version 7.10.5 patch_release_6068
Version 7.10.5 patch_release_6072
Version 7.10.5 patch_release_6079
Version 7.10.5 patch_release_6084
Version 7.10.5 patch_release_6092
Version 7.10.5 patch_release_6101
Version 7.10.5 patch_release_6111
Version 7.10.5 patch_release_6120
Version 7.10.5 patch_release_6132
Version 7.10.5 patch_release_6137
Version 7.10.5 patch_release_6140
Version 7.10.5 patch_release_6149
Version 7.10.6
Version 7.10.6 patch_release_6069
Version 7.10.6 patch_release_6073
Version 7.10.6 patch_release_6080
Version 7.10.6 patch_release_6085
Version 7.10.6 patch_release_6093
Version 7.10.6 patch_release_6102
Version 7.10.6 patch_release_6112
Version 7.10.6 patch_release_6121
Version 7.10.6 patch_release_6133
Version 7.10.6 patch_release_6138
Version 7.10.6 patch_release_6141
Version 7.10.6 patch_release_6146
Version 7.10.6 patch_release_6147
Version 7.10.6 patch_release_6148
Version 7.10.6 patch_release_6150

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory

Timeline

No history available yet.