First published: Fri May 02 2014(Updated: )
Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspecified API calls.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | =3.0.0 | |
Cybozu Garoon | =3.0.1 | |
Cybozu Garoon | =3.0.2 | |
Cybozu Garoon | =3.0.3 | |
Cybozu Garoon | =3.1.0 | |
Cybozu Garoon | =3.1.1 | |
Cybozu Garoon | =3.1.2 | |
Cybozu Garoon | =3.1.3 | |
Cybozu Garoon | =3.5.0 | |
Cybozu Garoon | =3.5.1 | |
Cybozu Garoon | =3.5.2 | |
Cybozu Garoon | =3.5.3 | |
Cybozu Garoon | =3.5.4 | |
Cybozu Garoon | =3.5.5 | |
Cybozu Garoon | =3.7-sp1 | |
Cybozu Garoon | =3.7-sp2 | |
Cybozu Garoon | =3.7-sp3 | |
Cybozu Garoon | =3.7.0 | |
Cybozu Garoon | =3.7.1 | |
Cybozu Garoon | =3.7.2 | |
=3.0.0 | ||
=3.0.1 | ||
=3.0.2 | ||
=3.0.3 | ||
=3.1.0 | ||
=3.1.1 | ||
=3.1.2 | ||
=3.1.3 | ||
=3.5.0 | ||
=3.5.1 | ||
=3.5.2 | ||
=3.5.3 | ||
=3.5.4 | ||
=3.5.5 | ||
=3.7-sp1 | ||
=3.7-sp2 | ||
=3.7-sp3 | ||
=3.7.0 | ||
=3.7.1 | ||
=3.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1989 is considered to have a medium severity due to its ability for remote authenticated users to manipulate scheduled information.
To fix CVE-2014-1989, it is recommended to upgrade to the latest version of Cybozu Garoon that addresses this vulnerability.
CVE-2014-1989 affects Cybozu Garoon versions from 3.0 through 3.7 SP3.
CVE-2014-1989 allows remote authenticated users to bypass access restrictions, leading to unauthorized deletion of schedule information.
Yes, CVE-2014-1989 can be exploited remotely by authenticated users.