CVE-2016-6190: Inverse-Inc Sogo
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.
Affected products
- Inverse-Inc Sogo: up to and including 2.3.11; version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.1.0 only
Published 2017-02-17. Last modified 2026-06-17.