First published: Mon May 24 2010(Updated: )
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Cybozu Office | =7 | |
Cybozu Cybozu Dotsales |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2029 is considered a critical vulnerability due to the potential for remote authentication bypass and unauthorized access to sensitive information.
To fix CVE-2010-2029, ensure that access control measures are properly enforced on the login page and update to the latest version of the affected software.
CVE-2010-2029 affects Cybozu Office version 7 and all versions of Cybozu Dotsales.
CVE-2010-2029 can be exploited by remote attackers who utilize the unique ID of a user's cell phone to access the login page without authorization.
Yes, user information is at risk as attackers may obtain or modify sensitive data through unauthorized access.