4
CVE-2014-9466
- EPSS 2.13%
- Veröffentlicht 17.02.2015 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open-xchange ≫ Open-xchange Appsuite Version 7.4.2
Open-xchange ≫ Open-xchange Appsuite Version 7.6.0
Open-xchange ≫ Open-xchange Appsuite Version 7.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.13% | 0.796 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
http://packetstormsecurity.com/files/130379/Open-Xchange-Server-6-OX-AppSuite-7.6.1-Exposure.html
http://www.securityfocus.com/archive/1/534695/100/0/threaded
http://www.securityfocus.com/bid/72587
http://www.securitytracker.com/id/1031744
https://exchange.xforce.ibmcloud.com/vulnerabilities/100867