Lucene search

K
jvnJapan Vulnerability NotesJVN:29845579
HistoryAug 06, 2024 - 12:00 a.m.

JVN#29845579: Cybozu Office vulnerable to bypass browsing restrictions in Custom App

2024-08-0600:00:00
Japan Vulnerability Notes
jvn.jp
6
cybozu office
vulnerability
bypass browsing restrictions
custom app
cwe-201
update software
products affected.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

18.9%

Cybozu Office provided by Cybozu, Inc. contains a vulnerability which allows to bypass browsing restrictions in Custom App (CWE-201).

Impact

A user who can login to the product may view data that the user does not have access by conducting ‘search’ under certain conditions.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Products Affected

  • Cybozu Office 10.0.0 to 10.8.6

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

18.9%

Related for JVN:29845579