« Volver al listado

CVE-2014-5237

Estado: ModificadaMedia (4.3)—

Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5237",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-12-01T15:59:04.297",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/533443/100/0/threaded",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/128257/Open-Xchange-7.6.0-XSS-SSRF-Traversal.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://software.open-xchange.com/OX6/doc/Release_Notes_for_Patch_Release_2112_7.6.0_2014-08-25.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/533443/100/0/threaded",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de SSRF en el componente documentconverter en Open-Xchange (OX) AppSuite anterior a 7.4.2-rev10 y 7.6.x anterior a 7.6.0-rev10 permite a atacantes remotos provocar solicitudes a servidores arbitrarios y anidar imágenes arbitrarias a través de una URL en una imagen anidiada en un documento de texto, lo que no se maneja debidamente en la vista previa de la imagen."
    }
  ],
  "lastModified": "2026-06-17T00:11:15.163",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.4.2:rev6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "344FE062-C444-4923-BD0C-1973A7BC4E09"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.4.2:rev7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C8E95EA-B1F4-4BD5-8EC3-111E3B74AC80"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.4.2:rev8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDDBA2B9-1503-4263-9A03-14E256BC72F2"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.4.2:rev9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "322430D3-92C2-447C-94EF-D59E33BC694C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.6.0:rev6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3438EF85-1272-40A8-8F39-5B7566812A9B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.6.0:rev7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E8674A3-DC4C-469A-BBAF-405F0D7304B5"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.6.0:rev8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58017BC3-893B-43C2-AAA0-B69C6B7FEF6B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:app_suite:7.6.0:rev9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2133F2D6-F156-4BEB-B6FC-BA827CD06574"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/918.html\" rel=\"nofollow\">CWE-918: Server-Side Request Forgery (SSRF)</a>",
  "sourceIdentifier": "cve@mitre.org"
}