Back to Database
Status published
Medium
CVE-2021-38376
OX App Suite through 7.10.5 has Incorrect Access Control for...
Vulnerability Description
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-38376
Credits & Attribution
No credits recorded in the NVD database.
References
More from open-xchange
View All →CVE-2022-43699
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account...
Unknown
0
CVE-2022-43698
OX App Suite before 7.10.6-rev30 allows SSRF because changing a...
Unknown
0
CVE-2022-43697
OX App Suite before 7.10.6-rev30 allows XSS via an activity...
Unknown
0
CVE-2022-43696
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads....
Unknown
0
CVE-2022-37313
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF...
Unknown
0
Affected Vendor
open-xchange
View all reports →Affected Software
ox app suite
Vulnerable Versions:
0
Timeline
Official Publish:
November 22nd, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.