CVE-2014-9466: Open-Xchange Appsuite
Medium severity, CVSS 4.0. EPSS: 2.1% chance of exploitation in the next 30 days.
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."
Affected products
- Open-Xchange Open-Xchange Appsuite: version 7.4.2 only; version 7.6.0 only; version 7.6.1 only
Published 2015-02-17. Last modified 2026-06-17.