PT-2013-5917 · Cybozu · Cybozu Garoon
Published
2013-12-28
·
Updated
2013-12-30
·
CVE-2013-6006
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cybozu Garoon versions 3.5 through 3.7 SP2
Description
The issue allows remote attackers to bypass Keitai authentication. This is achieved by modifying the
user ID in a request.Recommendations
For versions 3.5 through 3.7 SP2, consider restricting access to authentication mechanisms to minimize the risk of exploitation until a patch is available.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cybozu Garoon