CVE-2014-9049

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
owncloudowncloud_server
6.0.0
owncloudowncloud_server
6.0.1
owncloudowncloud_server
6.0.2
owncloudowncloud_server
6.0.3
owncloudowncloud_server
6.0.4
owncloudowncloud_server
6.0.5
owncloudowncloud_server
7.0.0
owncloudowncloud_server
7.0.1
owncloudowncloud_server
7.0.2
𝑥
= Vulnerable software versions