Vulnerability Details CVE-2014-9466
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 79.7%
CVSS Severity
CVSS v2 Score 4.0
Products affected by CVE-2014-9466
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0
-
cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.1