Vulnerabilities > Open Xchange > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2017-8777 Improper Authorization vulnerability in Open-Xchange OX Cloud 1.4.0
Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.
network
low complexity
open-xchange CWE-285
7.2
2019-05-22 CVE-2017-8340 Improper Access Control vulnerability in Open-Xchange Appsuite
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
network
low complexity
open-xchange CWE-284
8.8
2019-05-22 CVE-2017-6912 Improper Access Control vulnerability in Open-Xchange Appsuite
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
network
low complexity
open-xchange CWE-284
8.8
2019-05-10 CVE-2017-12884 Information Exposure vulnerability in Open-Xchange Appsuite
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.
network
low complexity
open-xchange CWE-200
7.5
2018-06-16 CVE-2018-5752 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.
network
low complexity
open-xchange CWE-918
8.8
2016-12-15 CVE-2016-4028 Credentials Management vulnerability in Open-Xchange OX Guard 2.4.0
An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8.
network
high complexity
open-xchange CWE-255
7.5
2016-12-15 CVE-2016-3174 Open Redirect vulnerability in Open-Xchange Appsuite
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27.
network
low complexity
open-xchange CWE-601
7.4
2016-12-15 CVE-2015-8542 Key Management Errors vulnerability in Open-Xchange OX Guard 2.0.0/2.2.0
An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.
network
low complexity
open-xchange CWE-320
8.8