2018-06-16 03:29:06 2018-08-03 19:09:07

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.

Vector

NETWORK

Complexity

LOW

Authentication

SINGLE_INSTANCE

Confidentiality

PARTIAL

Integrity

PARTIAL

Availability

PARTIAL
Open-xchange Open-xchange appsuite 7.6.3 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev14 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev15 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev16 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev17 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev18 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev20 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev22 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev23 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev24 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev25 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev26 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev28 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev29 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev30 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev31 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev32 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev33 (not an official CPE) Open-xchange Open-xchange appsuite 7.6.3 Rev35 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.0 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.2 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev10 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev11 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev12 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev13 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev14 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev15 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev16 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev17 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev18 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev19 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev20 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev21 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev22 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev23 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev24 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev25 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev26 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev27 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev28 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev29 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev30 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev31 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev32 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev33 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev34 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev35 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev36 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev38 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev39 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev40 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev41 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev42 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev43 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev5 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev6 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev8 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.3 Rev9 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev10 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev11 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev13 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev14 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev15 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev16 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev17 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev18 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev19 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev20 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev21 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev3 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev4 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev5 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev6 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev7 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev8 (not an official CPE) Open-xchange Open-xchange appsuite 7.8.4 Rev9 (not an official CPE)