Vulnerabilities > Open Xchange > Open Xchange Appsuite Backend

DATE CVE VULNERABILITY TITLE RISK
2023-08-02 CVE-2023-26430 Command Injection vulnerability in Open-Xchange Appsuite Backend 7.10.6/8.10.0
Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules.
network
low complexity
open-xchange CWE-77
4.3
2023-08-02 CVE-2023-26438 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Open-Xchange Appsuite Backend 7.10.6/8.10.0
External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache.
network
high complexity
open-xchange CWE-367
3.1
2023-08-02 CVE-2023-26443 SQL Injection vulnerability in Open-Xchange Appsuite Backend
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements.
network
low complexity
open-xchange CWE-89
critical
9.8
2023-08-02 CVE-2023-26451 Use of Insufficiently Random Values vulnerability in Open-Xchange Appsuite Backend
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service.
network
low complexity
open-xchange CWE-330
7.5
2023-06-20 CVE-2023-26427 Incorrect Permission Assignment for Critical Resource vulnerability in Open-Xchange Appsuite Backend
Default permissions for a properties file were too permissive.
local
low complexity
open-xchange CWE-732
3.3
2023-06-20 CVE-2023-26428 Authorization Bypass Through User-Controlled Key vulnerability in Open-Xchange Appsuite Backend
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context.
network
low complexity
open-xchange CWE-639
6.5
2023-06-20 CVE-2023-26429 Command Injection vulnerability in Open-Xchange Appsuite Backend
Control characters were not removed when exporting user feedback content.
network
low complexity
open-xchange CWE-77
5.3
2023-06-20 CVE-2023-26431 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite Backend
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made.
network
low complexity
open-xchange CWE-918
4.3
2023-06-20 CVE-2023-26432 Unspecified vulnerability in Open-Xchange Appsuite Backend
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes.
network
low complexity
open-xchange
4.3
2023-06-20 CVE-2023-26433 Unspecified vulnerability in Open-Xchange Appsuite Backend
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes.
network
low complexity
open-xchange
4.3