PT-2019-9237 · Cybozu · Cybozu Remote Service

Kanta Nishitani

·

Publicado

2019-01-09

·

Atualizado

2020-08-24

·

CVE-2018-16172

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Remote Service versions 3.0.0 through 3.1.8
Description An issue was found in the client certificates management screen, where an improper countermeasure against clickjacking attacks was discovered. This allows remote attackers to trick a user into deleting a registered client certificate.
Recommendations For Cybozu Remote Service versions 3.0.0 through 3.1.8, update to a version that includes a proper countermeasure against clickjacking attacks to prevent remote attackers from tricking users into deleting registered client certificates.

Correção

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16172

Produtos afetados

Cybozu Remote Service