CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:C/I:P/A:N
AI Score
Confidence
Low
EPSS
Percentile
46.9%
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.
Vendor | Product | Version | CPE |
---|---|---|---|
cybozu | garoon | 3.0.0 | cpe:2.3:a:cybozu:garoon:3.0.0:*:*:*:*:*:*:* |
cybozu | garoon | 3.0.1 | cpe:2.3:a:cybozu:garoon:3.0.1:*:*:*:*:*:*:* |
cybozu | garoon | 3.0.2 | cpe:2.3:a:cybozu:garoon:3.0.2:*:*:*:*:*:*:* |
cybozu | garoon | 3.0.3 | cpe:2.3:a:cybozu:garoon:3.0.3:*:*:*:*:*:*:* |
cybozu | garoon | 3.1.0 | cpe:2.3:a:cybozu:garoon:3.1.0:*:*:*:*:*:*:* |
cybozu | garoon | 3.1.1 | cpe:2.3:a:cybozu:garoon:3.1.1:*:*:*:*:*:*:* |
cybozu | garoon | 3.1.2 | cpe:2.3:a:cybozu:garoon:3.1.2:*:*:*:*:*:*:* |
cybozu | garoon | 3.1.3 | cpe:2.3:a:cybozu:garoon:3.1.3:*:*:*:*:*:*:* |
cybozu | garoon | 3.5.0 | cpe:2.3:a:cybozu:garoon:3.5.0:*:*:*:*:*:*:* |
cybozu | garoon | 3.5.1 | cpe:2.3:a:cybozu:garoon:3.5.1:*:*:*:*:*:*:* |