CVE-2015-5649: High severity cybozu garoon vulnerability
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5649?
CVE-2015-5649 has a medium severity level due to its potential for LDAP injection attacks and unauthorized access to sensitive information.
How do I fix CVE-2015-5649?
To mitigate CVE-2015-5649, update Cybozu Garoon to version 4.0.4 or later, which addresses the authentication mishandling issue.
What are the affected versions of CVE-2015-5649?
CVE-2015-5649 affects Cybozu Garoon versions 3.x through 3.7.5 and 4.x through 4.0.3.
Who can exploit CVE-2015-5649?
CVE-2015-5649 can be exploited by remote authenticated users with certain group-administration privileges.
What kind of attack can CVE-2015-5649 facilitate?
CVE-2015-5649 can facilitate LDAP injection attacks, leading to login restriction bypass and potential data leakage.