Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-6241

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2013-6241
Last Modified 29 Dec 2014 06:00:55
Published 27 Dec 2014 01:59:05
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2013-6241

Summary

The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315.

Vulnerable Systems

Application

  • Open-xchange Appsuite 7.2.0

  • Open-xchange Appsuite 7.2.1

  • Open-xchange Appsuite 7.2.2

  • Open-xchange Appsuite 7.4.0


References

CONFIRM - https://forum.open-xchange.com/showthread.php?8059-Open-Xchange-releases-Security-Patch-2013-10-21-for-v7-2-2-and-v7-4-0

BUGTRAQ - 20131106 Open-Xchange Security Advisory 2013-11-06


Last Updated: 27 May 2016 11:07:22