CVE-2023-29051

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
OXCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
open-xchangeox_app_suite
𝑥
< 7.10.6
open-xchangeox_app_suite
7.10.6
open-xchangeox_app_suite
7.10.6:rev01
open-xchangeox_app_suite
7.10.6:rev02
open-xchangeox_app_suite
7.10.6:rev03
open-xchangeox_app_suite
7.10.6:rev04
open-xchangeox_app_suite
7.10.6:rev05
open-xchangeox_app_suite
7.10.6:rev06
open-xchangeox_app_suite
7.10.6:rev07
open-xchangeox_app_suite
7.10.6:rev08
open-xchangeox_app_suite
7.10.6:rev09
open-xchangeox_app_suite
7.10.6:rev10
open-xchangeox_app_suite
7.10.6:rev11
open-xchangeox_app_suite
7.10.6:rev12
open-xchangeox_app_suite
7.10.6:rev13
open-xchangeox_app_suite
7.10.6:rev14
open-xchangeox_app_suite
7.10.6:rev15
open-xchangeox_app_suite
7.10.6:rev16
open-xchangeox_app_suite
7.10.6:rev17
open-xchangeox_app_suite
7.10.6:rev18
open-xchangeox_app_suite
7.10.6:rev19
open-xchangeox_app_suite
7.10.6:rev20
open-xchangeox_app_suite
7.10.6:rev21
open-xchangeox_app_suite
7.10.6:rev22
open-xchangeox_app_suite
7.10.6:rev23
open-xchangeox_app_suite
7.10.6:rev24
open-xchangeox_app_suite
7.10.6:rev25
open-xchangeox_app_suite
7.10.6:rev26
open-xchangeox_app_suite
7.10.6:rev27
open-xchangeox_app_suite
7.10.6:rev28
open-xchangeox_app_suite
7.10.6:rev29
open-xchangeox_app_suite
7.10.6:rev30
open-xchangeox_app_suite
7.10.6:rev31
open-xchangeox_app_suite
7.10.6:rev32
open-xchangeox_app_suite
7.10.6:rev33
open-xchangeox_app_suite
7.10.6:rev34
open-xchangeox_app_suite
7.10.6:rev35
open-xchangeox_app_suite
7.10.6:rev36
open-xchangeox_app_suite
7.10.6:rev37
open-xchangeox_app_suite
7.10.6:rev50
open-xchangeox_app_suite
8.17
𝑥
= Vulnerable software versions