First published: Fri Aug 16 2013(Updated: )
Cybozu Mailwise 5.0.4 and 5.0.5 allows remote authenticated users to obtain sensitive e-mail content intended for different persons in opportunistic circumstances by reading Subject header lines within the user's own mailbox.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Mailwise | =5.0.4 | |
Cybozu Mailwise | =5.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4698 is categorized as a moderate severity vulnerability due to its potential to expose sensitive email content.
Fixing CVE-2013-4698 involves updating your Cybozu Mailwise to the latest version that addresses the vulnerability.
CVE-2013-4698 is caused by improper restrictions on accessing email Subject header lines, allowing authenticated users to view unintended email contents.
CVE-2013-4698 affects users of Cybozu Mailwise versions 5.0.4 and 5.0.5.
The potential impacts of CVE-2013-4698 include unauthorized access to sensitive email information, which could lead to privacy breaches.