First published: Thu Feb 27 2014(Updated: )
Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | =2.0-sp1 | |
Cybozu Garoon | =2.0-sp2 | |
Cybozu Garoon | =2.0-sp3 | |
Cybozu Garoon | =2.0-sp4 | |
Cybozu Garoon | =2.0-sp5 | |
Cybozu Garoon | =2.0-sp6 | |
Cybozu Garoon | =2.0.0 | |
Cybozu Garoon | =2.0.1 | |
Cybozu Garoon | =2.0.2 | |
Cybozu Garoon | =2.0.3 | |
Cybozu Garoon | =2.0.4 | |
Cybozu Garoon | =2.0.5 | |
Cybozu Garoon | =2.0.6 | |
Cybozu Garoon | =2.1 | |
Cybozu Garoon | =2.1-sp1 | |
Cybozu Garoon | =2.1-sp2 | |
Cybozu Garoon | =2.1-sp3 | |
Cybozu Garoon | =2.1.0 | |
Cybozu Garoon | =2.1.1 | |
Cybozu Garoon | =2.1.2 | |
Cybozu Garoon | =2.1.3 | |
Cybozu Garoon | =2.5 | |
Cybozu Garoon | =2.5-sp1 | |
Cybozu Garoon | =2.5-sp2 | |
Cybozu Garoon | =2.5-sp3 | |
Cybozu Garoon | =2.5-sp4 | |
Cybozu Garoon | =2.5.0 | |
Cybozu Garoon | =2.5.1 | |
Cybozu Garoon | =2.5.2 | |
Cybozu Garoon | =2.5.3 | |
Cybozu Garoon | =2.5.4 | |
Cybozu Garoon | =3.0 | |
Cybozu Garoon | =3.0-sp1 | |
Cybozu Garoon | =3.0-sp2 | |
Cybozu Garoon | =3.0-sp3 | |
Cybozu Garoon | =3.1 | |
Cybozu Garoon | =3.1-sp1 | |
Cybozu Garoon | =3.1-sp2 | |
Cybozu Garoon | =3.1-sp3 | |
Cybozu Garoon | =3.5 | |
Cybozu Garoon | =3.5-sp1 | |
Cybozu Garoon | =3.5-sp2 | |
Cybozu Garoon | =3.5-sp3 | |
Cybozu Garoon | =3.5-sp4 | |
Cybozu Garoon | =3.5-sp5 | |
Cybozu Garoon | =3.5.3 | |
Cybozu Garoon | =3.7 | |
Cybozu Garoon | =3.7-sp1 | |
Cybozu Garoon | =3.7-sp2 | |
Cybozu Garoon | =3.7-sp3 | |
=2.0-sp1 | ||
=2.0-sp2 | ||
=2.0-sp3 | ||
=2.0-sp4 | ||
=2.0-sp5 | ||
=2.0-sp6 | ||
=2.0.0 | ||
=2.0.1 | ||
=2.0.2 | ||
=2.0.3 | ||
=2.0.4 | ||
=2.0.5 | ||
=2.0.6 | ||
=2.1 | ||
=2.1-sp1 | ||
=2.1-sp2 | ||
=2.1-sp3 | ||
=2.1.0 | ||
=2.1.1 | ||
=2.1.2 | ||
=2.1.3 | ||
=2.5 | ||
=2.5-sp1 | ||
=2.5-sp2 | ||
=2.5-sp3 | ||
=2.5-sp4 | ||
=2.5.0 | ||
=2.5.1 | ||
=2.5.2 | ||
=2.5.3 | ||
=2.5.4 | ||
=3.0 | ||
=3.0-sp1 | ||
=3.0-sp2 | ||
=3.0-sp3 | ||
=3.1 | ||
=3.1-sp1 | ||
=3.1-sp2 | ||
=3.1-sp3 | ||
=3.5 | ||
=3.5-sp1 | ||
=3.5-sp2 | ||
=3.5-sp3 | ||
=3.5-sp4 | ||
=3.5-sp5 | ||
=3.5.3 | ||
=3.7 | ||
=3.7-sp1 | ||
=3.7-sp2 | ||
=3.7-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0817 has a medium severity level as it allows authenticated users to impersonate arbitrary users.
To fix CVE-2014-0817, you should upgrade to a patched version of Cybozu Garoon that addresses the session management vulnerability.
CVE-2014-0817 affects Cybozu Garoon versions 2.x through 2.5.4 and 3.x through 3.7 SP3.
CVE-2014-0817 is a session management vulnerability that enables session hijacking by authenticated users.
Yes, CVE-2014-0817 can be exploited remotely by authenticated users to impersonate other users.