CVE-2016-4047
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As a result an attacker can track access to a manipulated document. Usage of a document may get tracked and information about internal infrastructure may get exposed.
Ha sido descubierto un problema en Open-Xchange OX App Suite en versiones anteriores a 7.8.1-rev8. Referencias a un documento de tipo de definiciones Open XML externo (recursos .dtd) pueden ser puestas dentro de archivos .docx y .xslx. Estos recursos se solicitaron al analizar ciertas partes del documento generado. Como resultado, un atacante puede rastrear el acceso a un documento manipulado. El uso de un documento puede ser rastreado y la informaciĆ³n sobre la infraestructura interna puede quedar expuesta.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-04-20 CVE Reserved
- 2016-12-15 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/538732/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id/1036157 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | <= 7.8.1 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version " <= 7.8.1" | rev7 |
Affected
|