#VU13546 XXE attack in Open-Xchange App Suite


Published: 2018-07-03

Vulnerability identifier: #VU13546

Vulnerability risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-9998

CWE-ID: CWE-611

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Open-Xchange App Suite
Client/Desktop applications / Software for system administration

Vendor: Open-Xchange Inc

Description

The disclosed vulnerability allows a remote authenticated attacker to perform XXE attack.

The vulnerability exists due to an error when requesting task folders. A remote attacker can send specially crafted XML external entity data and cause the target system to disclose the name of 'foreign' folders belonging to other users in the same context.

Mitigation
Update to versions 7.6.3-rev37, 7.8.2-rev40, 7.8.3-rev48, 7.8.4-rev28.

Vulnerable software versions

Open-Xchange App Suite: All versions


External links
http://seclists.org/fulldisclosure/2018/Jul/12


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability