PT-2019-9237 · Cybozu · Cybozu Remote Service
Kanta Nishitani
·
Published
2019-01-09
·
Updated
2020-08-24
·
CVE-2018-16172
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cybozu Remote Service versions 3.0.0 through 3.1.8
Description
An issue was found in the client certificates management screen, where an improper countermeasure against clickjacking attacks was discovered. This allows remote attackers to trick a user into deleting a registered client certificate.
Recommendations
For Cybozu Remote Service versions 3.0.0 through 3.1.8, update to a version that includes a proper countermeasure against clickjacking attacks to prevent remote attackers from tricking users into deleting registered client certificates.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cybozu Remote Service