PT-2019-17948 · Cybozu · Cybozu Office
Tanghaifeng
·
Published
2019-12-26
·
Updated
2020-08-24
·
CVE-2019-6023
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cybozu Office versions 10.0.0 through 10.8.3
Description
The issue allows remote authenticated attackers to bypass access restrictions, potentially resulting in obtaining data without proper access privileges. This is achieved via the application 'Address'.
Recommendations
For Cybozu Office versions 10.0.0 through 10.8.3, consider restricting access to the 'Address' application until a patch is available. As a temporary workaround, review and enforce strict access controls to minimize the risk of unauthorized data access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cybozu Office