Release date:
Updated on:
Affected Systems:
Open-xchange OX App Suite <7.4.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66698
CVE (CAN) ID: CVE-2014-2392
Open-Xchange Server is a part of Open-source projects that mainly develop collaborative software, such as email and calendar.
The Open-Xchange AppSuite 7.4.2 and earlier versions have the information leakage vulnerability. remote users can exploit this vulnerability to access sensitive information. This vulnerability is caused by the parameter communication provided by the application for GET requests when an email is automatically configured, which may cause account password leakage.
<* Source: Martin Braun
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Open-xchange
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.open-xchange.com/home.html