Open Xchange Server

Vendor:

First CVE: Sep 5, 2013 · Active for 12 years

13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
4.3
Avg CVSS
Higher Avg CVSS than 4% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Open Xchange Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2013
12 years ago
Most Recent CVE
Jun 8, 2017
3,335 days ago

CVE Severity & Scoring

Open Xchange Server13 CVEs
All CVEs352,719 CVEs
LowMedium
Attack Vector
Local0 (0.0%)
Network1 (7.7%)
Unknown12 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.7%)
High0 (0.0%)
Unknown12 (92.3%)
User Interaction
None0 (0.0%)
Unknown12 (92.3%)
Required1 (7.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (7.7%)
Unknown12 (92.3%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP hea
Sep 5, 20135.025NOYES
OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-midd
Sep 5, 20135.824NOYES
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files
Sep 5, 20134.024NOYES
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-de
Sep 5, 20134.321NOYES
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allo
Sep 5, 20133.521NOYES
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitr
Sep 5, 20134.321NOYES
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows r
Sep 5, 20135.018NONO
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
Jun 8, 20176.117NONO
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2
Sep 5, 20134.317NONO
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local
Sep 5, 20132.117NOYES

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
53.8% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Open Xchange Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2.023.90.9%00
7.0.244.30.9%00
7.0.144.30.9%00
6.22.1316.11.5%00
6.22.1216.11.5%00
6.22.1114.21.3%07
6.22.0114.21.3%07
6.20.794.21.4%07
6.016.11.5%00