PT-2015-7012 · Cybozu · Cybozu Garoon

Published

2015-10-08

·

Updated

2015-10-09

·

CVE-2015-5649

CVSS v2.0

7.0

High

VectorAV:N/AC:M/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Garoon versions 3.x through 3.7.5 Cybozu Garoon versions 4.x through 4.0.3
Description The issue concerns the mishandling of authentication requests, allowing remote authenticated users to conduct LDAP injection attacks. This can lead to the bypassing of intended login restrictions or the obtaining of sensitive information by leveraging certain group-administration privileges.
Recommendations For versions 3.x through 3.7.5, update to a version later than 3.7.5 to resolve the issue. For versions 4.x through 4.0.3, update to a version later than 4.0.3 to resolve the issue. As a temporary workaround, consider restricting group-administration privileges to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5649

Affected Products

Cybozu Garoon