« Volver al listado

CVE-2014-5236

Estado: ModificadaAlta (7.5)—

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5236",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-31T22:15:10.573",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/archive/1/533443/100/0/threaded",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/archive/1/533443/100/0/threaded",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de salto de ruta absoluto en documentconverter en Open-Xchange (OX) AppSuite versiones anteriores a 7.4.2-rev10 y versiones 7.6.x anteriores a 7.6.0-rev10, permiten a atacantes remotos leer archivos de aplicación por medio de un nombre de ruta completo en un (1) objeto OLE o (2) imagen diseñada en un archivo de texto OpenDocument."
    }
  ],
  "lastModified": "2026-06-17T00:11:15.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "567B4139-220A-46A7-B847-616F99A1EA66",
              "versionEndIncluding": "7.4.1"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A708019-6229-4768-994C-5A51B0495CAC"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4895984-4266-4924-A9C4-4DFEA90AFF79"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39A9F45E-5CAB-4BE5-8EAB-9E5ED43B4381"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72DB60BE-F818-4481-95BD-C0C1A42F2618"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B54DE9D-563C-45A9-BDED-3F216FECF28B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2A40E87-368E-4815-9988-1153E1866103"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E112E77E-C2CC-40D4-A8DC-F1FF76305CA8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76A099A1-23A0-4F0B-84C4-05C687F24F20"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0E95BA0-1517-4DAA-93B5-2B84DF4C3074"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F1899F3-6554-4C42-ACA2-4C22993D49DA"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.4.2:revision9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A45F679A-7F4D-49A5-8B95-E588102601F9"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0A22E01-73E0-4140-8BA1-AB147A9471CD"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91DC49BA-9FF4-4E0F-9723-E8F2970D6835"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB0ABA40-F8EF-4368-98A6-083F0E4528EF"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9E00E96-8D99-4579-8104-274908F3AAD5"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "733FEC4F-0DC2-49DE-8660-449CCE5A7F2F"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFA35536-65FA-4228-9C84-CC69C91B3A3F"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A6AABD0-D82F-465B-8B73-CA0B8A611DB8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85511C44-A366-4F62-944B-AEEDB8A6B938"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.0:revision8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3AD4BE8-CC1D-4FFA-B890-F565EA555366"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}