Vulnerabilities
Vulnerable Software
Open-Xchange:  Security Vulnerabilities
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-12-26
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-12-26
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
CVSS Score
5.3
EPSS Score
0.004
Published
2022-12-26
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-10-25
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
CVSS Score
9.8
EPSS Score
0.004
Published
2022-10-25
OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
CVSS Score
5.4
EPSS Score
0.007
Published
2022-07-27
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
CVSS Score
9.8
EPSS Score
0.025
Published
2022-07-27
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-07-27
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
CVSS Score
9.8
EPSS Score
0.08
Published
2022-07-27
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-07-27


Contact Us

Shodan ® - All rights reserved