CVE-2014-5238

XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
open-xchangeopen-xchange_appsuite
𝑥
≤ 7.4.1
open-xchangeopen-xchange_appsuite
7.4.2
open-xchangeopen-xchange_appsuite
7.4.2:revision1
open-xchangeopen-xchange_appsuite
7.4.2:revision10
open-xchangeopen-xchange_appsuite
7.4.2:revision2
open-xchangeopen-xchange_appsuite
7.4.2:revision3
open-xchangeopen-xchange_appsuite
7.4.2:revision4
open-xchangeopen-xchange_appsuite
7.4.2:revision5
open-xchangeopen-xchange_appsuite
7.4.2:revision6
open-xchangeopen-xchange_appsuite
7.4.2:revision7
open-xchangeopen-xchange_appsuite
7.4.2:revision8
open-xchangeopen-xchange_appsuite
7.4.2:revision9
open-xchangeopen-xchange_appsuite
7.6.0
open-xchangeopen-xchange_appsuite
7.6.0:revision1
open-xchangeopen-xchange_appsuite
7.6.0:revision2
open-xchangeopen-xchange_appsuite
7.6.0:revision3
open-xchangeopen-xchange_appsuite
7.6.0:revision4
open-xchangeopen-xchange_appsuite
7.6.0:revision5
open-xchangeopen-xchange_appsuite
7.6.0:revision6
open-xchangeopen-xchange_appsuite
7.6.0:revision7
open-xchangeopen-xchange_appsuite
7.6.0:revision8
𝑥
= Vulnerable software versions