PT-2019-9237 · Cybozu · Cybozu Remote Service

Kanta Nishitani

·

Published

2019-01-09

·

Updated

2020-08-24

·

CVE-2018-16172

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Remote Service versions 3.0.0 through 3.1.8
Description An issue was found in the client certificates management screen, where an improper countermeasure against clickjacking attacks was discovered. This allows remote attackers to trick a user into deleting a registered client certificate.
Recommendations For Cybozu Remote Service versions 3.0.0 through 3.1.8, update to a version that includes a proper countermeasure against clickjacking attacks to prevent remote attackers from tricking users into deleting registered client certificates.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16172

Affected Products

Cybozu Remote Service