First published: Tue Jun 18 2013(Updated: )
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Live | <=2.0.0 | |
Cybozu Live | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3646 is rated as a high-severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2013-3646, update the Cybozu Live application to version 2.0.1 or later.
CVE-2013-3646 affects Cybozu Live versions prior to 2.0.1, including version 1.0.4.
CVE-2013-3646 allows attackers to execute arbitrary Java methods and potentially gain sensitive information.
Yes, CVE-2013-3646 exists due to a regression related to CVE-2012-4008.