First published: Fri Oct 21 2011(Updated: )
Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to manipulation of a URL.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Office | <=7 | |
Cybozu Office | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2677 is classified as a medium severity vulnerability due to its potential to expose sensitive information to authenticated users.
To mitigate CVE-2011-2677, upgrade to Cybozu Office version 8.0.0 or later to enforce proper access restrictions.
CVE-2011-2677 affects users of Cybozu Office versions prior to 8.0.0 and specifically targets versions 6.x and up to version 7.x.
CVE-2011-2677 allows unauthorized access to sensitive information such as time card and attendance records.
CVE-2011-2677 results from flawed access controls, allowing remote authenticated users to manipulate URLs and access restricted data.