- Description
- Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 has a hardcoded password for node join operations, which allows remote attackers to expand a cluster by finding this password in the source code and then sending the password in a Hazelcast cluster API call, a different vulnerability than CVE-2013-5200.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 4.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:N
- nvd@nist.gov
- CWE-255
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "138461CD-9C27-40E5-B7A0-A37737B6E942"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "108BCEFD-3098-4919-9B0C-E80F6FA1C102"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDBB02DF-1022-4FE5-B5E1-198DC58F8C1B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BF31219-8390-4676-A9C4-D625A016C71E"
}
],
"operator": "OR"
}
]
}
]