BugTraq
Open-Xchange Security Advisory 2015-09-23 Sep 23 2015 09:56AM
Martin Heiland (martin heiland lists open-xchange com)
Vendor: Open-Xchange GmbH

Product: Open-Xchange Server 6 / OX AppSuite
Internal reference: 39485 (Bug ID)
Vulnerability type: Cross-Site Scripting (CWE-80)
Vulnerable version: OX6 6.22.9, AppSuite 7.6.2 and earlier
Vulnerable component: frontend
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 6.22.8-rev8, 6.22.9-rev15m, 7.6.1-rev25, 7.6.2-rev20
Vendor notification: 2015-07-07
Solution date: 2015-07-24
CVE reference: CVE-2015-5375
CVSSv2: 5.7 (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:U/RC:C/CDP:LM/TD:H/CR:ND/IR:ND/AR:N
D)

Vulnerability Details:
Dialogs for printing content were vulnerable to execute injected script code at object properties that get printed.

Risk:
Malicious script code can be executed within a users context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). Potential attack vectors are E-Mail (via attachments) or Drive.

Solution:
Providers should update to the latest Patch Releases 6.22.8-rev8, 6.22.9-rev15m, 7.6.1-rev25, 7.6.2-rev20 (or later).

Product: Guard
Internal reference: 40003 (Bug ID)
Vulnerability type: SQL Injection (CWE-89)
Vulnerable version: 2.0.0-rev7 and earlier
Vulnerable component: guard
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.0.0-rev8
Vendor notification: 2015-07-28
Solution date: 2015-08-03
CVE reference: CVE-2015-5703
CVSSv2: 7.9 (AV:N/AC:H/Au:M/C:P/I:C/A:N/E:F/RL:U/RC:C/CDP:MH/TD:ND/CR:H/IR:H/AR:M)

Vulnerability Details:
A SQL injection vulnerability at the public key discovery API call has been identified that allows to execute arbitrary SQL statements in the context of the OX Guard database user. Valid user credentials are required to access this API and execute malicious statements.

Risk:
The vulnerability can be exploited to access confidential information like system configuration, mail addresses or other database content. Credentials are stored as salted hashes and PGP keys are stored encrypted. This makes it very expensive to extract plain-text data from it. There is no indicator that this vulnerability was been publicly known or exploited.

Solution:
Providers should update to Patch Release 2.0.0-rev8, or any later version.
-----BEGIN PGP SIGNATURE-----
Version: BCPG v1.52

iQIcBAABCAAGBQJWAndJAAoJEAJhPBDDBiJjwncP/1fx2N0XRZBoM6hWdaII256t
PcDcvtUjrfwod2LSC9CcLDZci1duPxW5AehhCKOXrUUh/3A6wVR9OVU1AeY7jfl7
uLBwM5kThQWiWqNf9YxRJLM+ybckAK+eUt2TwLQkEfFeqLr9wbmze3VcJ6kJpBSi
AoI8O+pP03o7wSZUoRlgOjOSyokh9X8arFMP9l9j10jSjEXLR12pOPYZYfaHR5i6
4bB1EcZEZMAEMuo6BIvOSidH1szvBYg8LJix6VdL8ywLrgNPe7qVu2JPO0nshUas
+8bKR+AgLbcDYzxB5YzuiPmx6CbKd6Srp/uHbG7NuU4xv7eC45HW2uHjvj+owMSE
yb1qnTMPYHXP3lghCf8Z+GVxmlwBjMmlrWFgq6qs3wKnlpWad8KvsZGZ4CId2WO8
Ju5954K4P2UDPOfo6wSerrw2kgw/U7zM2fWLErDOOyD27dc7MIPdouGaVmt0n3cs
u9TVzF870Ef0Hz27ZVh4bnleqUlp1LGHRim1FdhntB5MiQIU3xWSC6JwV2vHp8tR
5jTBloqjjY627UZ9BRxbopESHKFR4V8k2z+8T4wIeiMjoESl9BGIDcT7O0Lyw3J0
3y3Jn2UI7DtkrfKrA77+vrHyfChYQivJhu86kBofxqDDG/lz70Hv+KbOQ57YoMdD
7U2gVeMI3lt0MmYjZMAc
=SnhL
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus