CVE-2014-1987: OS Command Injection
Published Jul 20, 2014
·Updated
The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.
Affected Software
13 affected components
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7-sp1
Cybozu Garoon=3.7-sp2
Cybozu Garoon=3.7-sp3
Event History
Jul 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1987?
CVE-2014-1987 has a medium severity rating, indicating potential for significant impact if exploited.
2
How do I fix CVE-2014-1987?
To fix CVE-2014-1987, upgrade to a version of Cybozu Garoon that is patched against this vulnerability, such as version 3.7 SP4 or later.
3
What types of attacks can exploit CVE-2014-1987?
CVE-2014-1987 can be exploited through remote command execution, allowing attackers to execute arbitrary commands on the server.
4
Which versions of Cybozu Garoon are affected by CVE-2014-1987?
CVE-2014-1987 affects Cybozu Garoon versions 3.1.0 through 3.7 SP3.
5
Is authentication required to exploit CVE-2014-1987?
Exploitation of CVE-2014-1987 can occur remotely without authentication, making it particularly dangerous.