{"id":"CVE-2016-6190","details":"SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the \"View the Date & Time\" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.","modified":"2026-07-08T12:42:08.675425Z","published":"2017-02-17T17:59:00.843Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_1:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_2:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_3:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_4:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.0.0-beta_1"},{"last_affected":"3.0.0-beta_1"},{"introduced":"3.0.0-beta_2"},{"last_affected":"3.0.0-beta_2"},{"introduced":"3.0.0-beta_3"},{"last_affected":"3.0.0-beta_3"},{"introduced":"3.0.0-beta_4"},{"last_affected":"3.0.0-beta_4"},{"introduced":"3.0.0-beta_5"},{"last_affected":"3.0.0-beta_5"}],"source":"CPE_STRING","vendor_product":"inverse-inc:sogo"}]},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/07/09/3"},{"type":"ADVISORY","url":"https://sogo.nu/bugs/view.php?id=3696"},{"type":"FIX","url":"https://github.com/inverse-inc/sogo/commit/717f45f640a2866b76a8984139391fae64339225"},{"type":"FIX","url":"https://github.com/inverse-inc/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/Alinto/sogo","events":[{"introduced":"0"},{"last_affected":"c5526bb70aef69b7be128f96a8d33ef99d4b97a5"},{"introduced":"fe0221f6300bc92f0156f9dde4e58c1c8d3610e7"},{"last_affected":"335621ba421f746b27dcc7184cde7ae769bf4538"}],"database_specific":{"cpe":["cpe:2.3:a:inverse-inc:sogo:*:*:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.1:*:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.0.2:*:*:*:*:*:*:*","cpe:2.3:a:inverse-inc:sogo:3.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.3.11"},{"introduced":"3.0.0"},{"last_affected":"3.0.0"},{"introduced":"3.0.1"},{"last_affected":"3.0.1"},{"introduced":"3.0.2"},{"last_affected":"3.0.2"},{"introduced":"3.1.0"},{"last_affected":"3.1.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["3.0.0","3.0.1","3.0.2","3.1.0","SOGo-3.1.0","SOGo-2.3.11","SOGo-2.3.10","SOGo-2.3.9","SOGo-3.0.2","SOGo-2.3.8","SOGo-3.0.1","SOGo-3.0.0","SOGo-2.3.7a","SOGo-2.3.7","SOGo-2.3.6","SOGo-2.3.5","SOGo-2.3.4","SOGo-2.3.3a","SOGo-2.3.3","SOGo-2.3.2","SOGo-2.3.1","SOGo-2.3.0","SOGo-2.2.17a","SOGo-2.2.20","SOGo-2.0.2","SOGo-2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6190.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/alinto/sogo","events":[{"introduced":"0"},{"fixed":"717f45f640a2866b76a8984139391fae64339225"},{"fixed":"875a4aca3218340fd4d3141950c82c2ff45b343d"}],"database_specific":{"source":"REFERENCES"}}],"versions":["SOGo-3.1.0","SOGo-2.3.11","SOGo-2.3.10","SOGo-2.3.9","SOGo-3.0.2","SOGo-2.3.8","SOGo-3.0.1","SOGo-3.0.0","SOGo-2.3.7a","SOGo-2.3.7","SOGo-2.3.6","SOGo-2.3.5","SOGo-2.3.4","SOGo-3.0.0b5","SOGo-3.0.0b4","SOGo-2.3.3a","SOGo-2.3.3","SOGo-3.0.0b3","SOGo-3.0.0b2","SOGo-2.3.2","SOGo-3.0.0b1","SOGo-2.3.1","SOGo-2.3.0","SOGo-2.2.17a","SOGo-2.2.20","SOGo-2.0.2","SOGo-2.0.1"],"database_specific":{"vanir_signatures_modified":"2026-07-08T12:42:08Z","vanir_signatures":[{"target":{"file":"SoObjects/SOGo/SOGoUserSettings.h"},"deprecated":false,"digest":{"line_hashes":["272275947418062989887012245545970907197","237761867161411648712498103835426187177","231454080872523687104751719403681284838","193563563261601370690713969555675233477"],"threshold":0.9},"id":"CVE-2016-6190-06b8778f","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/717f45f640a2866b76a8984139391fae64339225"},{"source":"https://github.com/alinto/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d","target":{"file":"SoObjects/SOGo/SOGoUserSettings.h"},"deprecated":false,"digest":{"line_hashes":["272275947418062989887012245545970907197","237761867161411648712498103835426187177","231454080872523687104751719403681284838","193563563261601370690713969555675233477"],"threshold":0.9},"id":"CVE-2016-6190-26f1ac38","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6190.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}