Lucene search

K
jvnJapan Vulnerability NotesJVN:91153528
HistoryJan 28, 2014 - 12:00 a.m.

JVN#91153528: Multiple SQL injection vulnerabilities in Cybozu Garoon

2014-01-2800:00:00
Japan Vulnerability Notes
jvn.jp
20

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

69.6%

Cybozu Garoon contains issues in the process of page navigation link and input through API, which may result in SQL injection.

Impact

A user who can log in to the system may obtain or alter data in the database.

Solution

Apply the Patch
Apply the appropriate patch according to the information provided by the developer.

Products Affected

  • Cybozu Garoon version 3.7 Service Pack 2 and earlier

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

69.6%

Related for JVN:91153528