CVE Database
/

CVE-2022-37400

Back to search

CVE-2022-37400

Published: Aug 13, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice

VendorProductVersions

Apache Software Foundation

Apache OpenOffice

affected
Apache OpenOffice 4 - < 4.1.13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now