Lucene search

K
cveJpcertCVE-2016-4868
HistoryApr 17, 2017 - 3:59 p.m.

CVE-2016-4868

2017-04-1715:59:00
CWE-20
jpcert
web.nvd.nist.gov
28
cybozu office
email header injection
vulnerability
remote attackers
cve-2016-4868
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.8

Confidence

High

EPSS

0.002

Percentile

55.6%

Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

Affected configurations

Nvd
Node
cybozuofficeMatch9.0
OR
cybozuofficeMatch9.1.0
OR
cybozuofficeMatch9.2.0
OR
cybozuofficeMatch9.2.1
OR
cybozuofficeMatch9.3.0
OR
cybozuofficeMatch9.3.1
OR
cybozuofficeMatch9.3.2
OR
cybozuofficeMatch9.9.0
OR
cybozuofficeMatch10.0.0
OR
cybozuofficeMatch10.0.1
OR
cybozuofficeMatch10.0.2
OR
cybozuofficeMatch10.1.0
OR
cybozuofficeMatch10.1.2
OR
cybozuofficeMatch10.2.0
OR
cybozuofficeMatch10.3.0
OR
cybozuofficeMatch10.4.0
VendorProductVersionCPE
cybozuoffice9.0cpe:2.3:a:cybozu:office:9.0:*:*:*:*:*:*:*
cybozuoffice9.1.0cpe:2.3:a:cybozu:office:9.1.0:*:*:*:*:*:*:*
cybozuoffice9.2.0cpe:2.3:a:cybozu:office:9.2.0:*:*:*:*:*:*:*
cybozuoffice9.2.1cpe:2.3:a:cybozu:office:9.2.1:*:*:*:*:*:*:*
cybozuoffice9.3.0cpe:2.3:a:cybozu:office:9.3.0:*:*:*:*:*:*:*
cybozuoffice9.3.1cpe:2.3:a:cybozu:office:9.3.1:*:*:*:*:*:*:*
cybozuoffice9.3.2cpe:2.3:a:cybozu:office:9.3.2:*:*:*:*:*:*:*
cybozuoffice9.9.0cpe:2.3:a:cybozu:office:9.9.0:*:*:*:*:*:*:*
cybozuoffice10.0.0cpe:2.3:a:cybozu:office:10.0.0:*:*:*:*:*:*:*
cybozuoffice10.0.1cpe:2.3:a:cybozu:office:10.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.8

Confidence

High

EPSS

0.002

Percentile

55.6%

Related for CVE-2016-4868