CVE-2014-1996: High severity cybozu garoon vulnerability
Published Jul 20, 2014
·Updated
Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial of service, via an API call.
Affected Software
4 affected components
Cybozu Garoon=3.7-sp1
Cybozu Garoon=3.7-sp2
Cybozu Garoon=3.7-sp3
Cybozu Garoon=3.7.0
Event History
Jul 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1996?
CVE-2014-1996 is considered a high severity vulnerability due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2014-1996?
To fix CVE-2014-1996, it is recommended to upgrade Cybozu Garoon to version 3.7 SP4 or later.
3
Who is affected by CVE-2014-1996?
CVE-2014-1996 affects users of Cybozu Garoon versions 3.7 SP1, SP2, SP3, and the initial 3.7.0 release.
4
Can CVE-2014-1996 be exploited remotely?
Yes, CVE-2014-1996 can be exploited remotely by authenticated users, allowing them to bypass access restrictions.
5
What are the consequences of exploiting CVE-2014-1996?
Exploiting CVE-2014-1996 can lead to arbitrary code execution on the server or result in a denial of service.