CVE-2013-3656: Medium severity cybozu office vulnerability
Published Jul 18, 2013
·Updated
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
Affected Software
1 affected component
Cybozu Cybozu Office<=9.1.0
Event History
Jul 18, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3656?
CVE-2013-3656 has a medium severity level as it allows remote attackers to bypass authentication.
2
How do I fix CVE-2013-3656?
To fix CVE-2013-3656, you should upgrade to Cybozu Office version 9.1.1 or later.
3
What software is affected by CVE-2013-3656?
CVE-2013-3656 affects Cybozu Office versions 9.1.0 and earlier.
4
What type of vulnerability is CVE-2013-3656?
CVE-2013-3656 is an authentication bypass vulnerability due to improper session management.
5
Can CVE-2013-3656 be exploited remotely?
Yes, CVE-2013-3656 can be exploited remotely by attackers who know the login URL.