Lucene search

K
nvd[email protected]NVD:CVE-2024-39817
HistoryAug 06, 2024 - 5:15 a.m.

CVE-2024-39817

2024-08-0605:15:41
web.nvd.nist.gov
5
cybozu office
sensitive information
data issue
custom app
cve-2024-39817
product login
data access

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

18.9%

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting ‘search’ under certain conditions in Custom App.

Affected configurations

Nvd
Node
cybozuofficeRange10.0.010.8.7
VendorProductVersionCPE
cybozuoffice*cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

18.9%

Related for NVD:CVE-2024-39817