PT-2019-17884 · Cybozu · Cybozu Garoon
Ixama
·
Publicado
2019-05-17
·
Atualizado
2020-08-24
·
CVE-2019-5943
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cybozu Garoon versions 4.0.0 through 4.10.1
Description
The issue allows remote authenticated attackers to bypass access restrictions, enabling them to view information without having the necessary view privileges. This is achievable through the 'Bulletin' and 'Cabinet' applications.
Recommendations
For versions 4.0.0 through 4.10.1, consider restricting access to the 'Bulletin' and 'Cabinet' applications until a fix is available, to minimize the risk of unauthorized information viewing.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cybozu Garoon