RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated to require authenticated requests. No publicly available exploits are known.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open-xchange_appsuite | Open-xchange | * | 7.10.6 (excluding) |
Open-xchange_appsuite | Open-xchange | 7.10.6 (including) | 7.10.6 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6069 (including) | 7.10.6-patch_release_6069 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6073 (including) | 7.10.6-patch_release_6073 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6080 (including) | 7.10.6-patch_release_6080 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6085 (including) | 7.10.6-patch_release_6085 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6093 (including) | 7.10.6-patch_release_6093 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6102 (including) | 7.10.6-patch_release_6102 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6112 (including) | 7.10.6-patch_release_6112 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6121 (including) | 7.10.6-patch_release_6121 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6133 (including) | 7.10.6-patch_release_6133 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6138 (including) | 7.10.6-patch_release_6138 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6141 (including) | 7.10.6-patch_release_6141 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6146 (including) | 7.10.6-patch_release_6146 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6147 (including) | 7.10.6-patch_release_6147 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6148 (including) | 7.10.6-patch_release_6148 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6150 (including) | 7.10.6-patch_release_6150 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6156 (including) | 7.10.6-patch_release_6156 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6161 (including) | 7.10.6-patch_release_6161 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6166 (including) | 7.10.6-patch_release_6166 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6173 (including) | 7.10.6-patch_release_6173 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6176 (including) | 7.10.6-patch_release_6176 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6178 (including) | 7.10.6-patch_release_6178 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6189 (including) | 7.10.6-patch_release_6189 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6194 (including) | 7.10.6-patch_release_6194 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6199 (including) | 7.10.6-patch_release_6199 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6204 (including) | 7.10.6-patch_release_6204 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6205 (including) | 7.10.6-patch_release_6205 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6209 (including) | 7.10.6-patch_release_6209 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6210 (including) | 7.10.6-patch_release_6210 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6214 (including) | 7.10.6-patch_release_6214 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6215 (including) | 7.10.6-patch_release_6215 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6216 (including) | 7.10.6-patch_release_6216 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6218 (including) | 7.10.6-patch_release_6218 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6219 (including) | 7.10.6-patch_release_6219 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6220 (including) | 7.10.6-patch_release_6220 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6227 (including) | 7.10.6-patch_release_6227 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6230 (including) | 7.10.6-patch_release_6230 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6233 (including) | 7.10.6-patch_release_6233 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6235 (including) | 7.10.6-patch_release_6235 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6236 (including) | 7.10.6-patch_release_6236 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6239 (including) | 7.10.6-patch_release_6239 (including) |
Open-xchange_appsuite | Open-xchange | 7.10.6-patch_release_6241 (including) | 7.10.6-patch_release_6241 (including) |