8.8
CVSSv3

CVE-2022-37400

Published: 15/08/2022 Updated: 02/08/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions before 4.1.13. Reference: CVE-2022-26306 - LibreOffice

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice