CVE-2022-37400
HIGHApache OpenOffice <4.1.13 - Info Disclosure
Title source: llmDescription
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice
Scores
CVSS v3
8.8
EPSS
0.0014
EPSS Percentile
33.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-330
Status
published
Affected Products (1)
apache/openoffice
< 4.1.13
Timeline
Published
Aug 15, 2022
Tracked Since
Feb 18, 2026