E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same ser…
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could p…
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers co…
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availabilit…
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please …
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existi…
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please d…
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with …
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could…
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i…
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature …
The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account,…
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could…
User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could …
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user…
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL sta…
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editi…
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that wou…
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected…
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerabi…
Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least a…
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at l…
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th…
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user int…
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes …
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can …
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within …
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within…
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abus…
The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement…