CVE-2013-1650 describes a weak permissions vulnerability in Open-Xchange Server versions prior to 6.20.7 rev14, 6.22.0 rev13, and 6.22.1 rev14. This flaw allows local users to access sensitive information due to group "other" having read permissions on files within the opt/open-xchange/etc/ directory. The vulnerability has a low severity CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of information disclosure. There is no evidence of active exploitation, and while an ExploitDB entry exists (EDB-24791) mentioning "Multiple Vulnerabilities" for Open-Xchange Server 6, specific exploit code for this CVE is not widely available, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.20.7CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_server:6.20.7:*:*:*:*:*:*:* | ||
6.22.0CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_server:6.22.0:*:*:*:*:*:*:* | ||
6.22.1CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_server:6.22.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.