OX App Suite: Processing Load Monitoring and Update Deployment
CVE-2023-41707

6.5MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2024

What is CVE-2023-41707?

The vulnerability allows unregulated processing of user-defined mail search expressions in OX App Suite, potentially leading to a significant performance hit due to increased processing loads. There are now measures to monitor the processing time of these expressions, with automatic termination of requests that exceed defined resource thresholds. Users are advised to apply the necessary patches promptly to enhance system stability and performance. No publicly available exploits are known for this vulnerability.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev55

OX App Suite 0 <= 7.6.3-rev71

OX App Suite 0 <= 8.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.