CVE-2013-5935
https://notcve.org/view.php?id=CVE-2013-5935
25 Sep 2013 — The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remote attackers to obtain access by sending network traffic from an unintended location, a different vulnerability than CVE-2013-5200. La API Hazelcast cluster en Open-Xchange AppSuite v7.0.x anterior a v7.0.2-rev15 y v7.2.x anterior a v7.2.2-rev16 no restringe correctamente el conjunto de inte... • http://archives.neohapsis.com/archives/bugtraq/2013-09/0032.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2013-5936
https://notcve.org/view.php?id=CVE-2013-5936
25 Sep 2013 — The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3) user sessions, (4) the memcache interface, and (5) the REST interface via API calls such as a hazelcast/rest/cluster/ call, a different vulnerability than CVE-2013-5200. La API Hazelcast cluster en Open-Xchange AppSuite v7.0.x anterior a v7.0.2-rev15 y v7.2.x anterior a v7.2.2-rev16 permite ... • http://archives.neohapsis.com/archives/bugtraq/2013-09/0032.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2013-5200 – Open-Xchange AppSuite 7.2.2 Improper Authentication / Information Disclosure
https://notcve.org/view.php?id=CVE-2013-5200
10 Sep 2013 — The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain sensitive information or modify data via an API call. Los interfaces (1) REST y (2) memcache en Hazelcast cluster API de Open-Xchange AppSuite 7.0.x (anteriores a 7.0.2-rev15) y 7.2.x (anteriores a 7.2.2-rev16) no requieren autenticación, lo que permite a atacantes remotos obtener informació... • http://archives.neohapsis.com/archives/bugtraq/2013-09/0032.html • CWE-287: Improper Authentication •
CVE-2013-4790 – Open-Xchange AppSuite 7.2.2 Phishing / Data Injection
https://notcve.org/view.php?id=CVE-2013-4790
01 Aug 2013 — Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote authenticated users to discover e-mail credentials of other users in opportunistic circumstances via a manual-mode association of a personal e-mail address with the hostname of a crafted IMAP server. Múltiples vulnerabilidades XSS en Open-Xchange AppSuite, 7.0.2 rev14, 7.2.0 anteior a rev11, 7... • http://archives.neohapsis.com/archives/bugtraq/2013-07/0204.html • CWE-255: Credentials Management Errors •