CVE-2014-0817: Medium severity Cybozu Garoon vulnerability
Published Feb 27, 2014
·Updated
Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors.
Affected Software
50 affected components
Cybozu Garoon=2.0-sp1
Cybozu Garoon=2.0-sp2
Cybozu Garoon=2.0-sp3
Cybozu Garoon=2.0-sp4
Cybozu Garoon=2.0-sp5
Cybozu Garoon=2.0-sp6
Cybozu Garoon=2.0.0
Cybozu Garoon=2.0.1
Cybozu Garoon=2.0.2
Cybozu Garoon=2.0.3
Cybozu Garoon=2.0.4
Cybozu Garoon=2.0.5
Cybozu Garoon=2.0.6
Cybozu Garoon=2.1
Cybozu Garoon=2.1-sp1
Cybozu Garoon=2.1-sp2
Cybozu Garoon=2.1-sp3
Cybozu Garoon=2.1.0
Cybozu Garoon=2.1.1
Cybozu Garoon=2.1.2
Cybozu Garoon=2.1.3
Cybozu Garoon=2.5
Cybozu Garoon=2.5-sp1
Cybozu Garoon=2.5-sp2
Cybozu Garoon=2.5-sp3
Cybozu Garoon=2.5-sp4
Cybozu Garoon=2.5.0
Cybozu Garoon=2.5.1
Cybozu Garoon=2.5.2
Cybozu Garoon=2.5.3
Cybozu Garoon=2.5.4
Cybozu Garoon=3.0
Cybozu Garoon=3.0-sp1
Cybozu Garoon=3.0-sp2
Cybozu Garoon=3.0-sp3
Cybozu Garoon=3.1
Cybozu Garoon=3.1-sp1
Cybozu Garoon=3.1-sp2
Cybozu Garoon=3.1-sp3
Cybozu Garoon=3.5
Cybozu Garoon=3.5-sp1
Cybozu Garoon=3.5-sp2
Cybozu Garoon=3.5-sp3
Cybozu Garoon=3.5-sp4
Cybozu Garoon=3.5-sp5
Cybozu Garoon=3.5.3
Cybozu Garoon=3.7
Cybozu Garoon=3.7-sp1
Cybozu Garoon=3.7-sp2
Cybozu Garoon=3.7-sp3
Remediation
Patch Available
Event History
Feb 27, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0817?
CVE-2014-0817 has a medium severity level as it allows authenticated users to impersonate arbitrary users.
2
How do I fix CVE-2014-0817?
To fix CVE-2014-0817, you should upgrade to a patched version of Cybozu Garoon that addresses the session management vulnerability.
3
Which versions are affected by CVE-2014-0817?
CVE-2014-0817 affects Cybozu Garoon versions 2.x through 2.5.4 and 3.x through 3.7 SP3.
4
What type of vulnerability is CVE-2014-0817?
CVE-2014-0817 is a session management vulnerability that enables session hijacking by authenticated users.
5
Can CVE-2014-0817 be exploited remotely?
Yes, CVE-2014-0817 can be exploited remotely by authenticated users to impersonate other users.