CVE-2010-2029: Medium severity Cybozu Cybozu Office vulnerability
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2029?
CVE-2010-2029 is considered a critical vulnerability due to the potential for remote authentication bypass and unauthorized access to sensitive information.
How do I fix CVE-2010-2029?
To fix CVE-2010-2029, ensure that access control measures are properly enforced on the login page and update to the latest version of the affected software.
Which versions of Cybozu Office are affected by CVE-2010-2029?
CVE-2010-2029 affects Cybozu Office version 7 and all versions of Cybozu Dotsales.
What type of attack can exploit CVE-2010-2029?
CVE-2010-2029 can be exploited by remote attackers who utilize the unique ID of a user's cell phone to access the login page without authorization.
Is user information at risk due to CVE-2010-2029?
Yes, user information is at risk as attackers may obtain or modify sensitive data through unauthorized access.