Vulnerabilities > CVE-2016-4046 - Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite 7.8.1

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
open-xchange
CWE-918

Summary

An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.

Vulnerable Configurations

Part Description Count
Application
Open-Xchange
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/137599/openxchange781-disclose.txt
idPACKETSTORM:137599
last seen2016-12-05
published2016-06-22
reporterMartin Heiland
sourcehttps://packetstormsecurity.com/files/137599/Open-Xchange-App-Suite-7.8.1-Information-Disclosure.html
titleOpen-Xchange App Suite 7.8.1 Information Disclosure