CVE-2015-8486: Medium severity cybozu office vulnerability
Published Feb 17, 2016
·Updated
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.
Affected Software
8 affected components
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Event History
Feb 17, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8486?
CVE-2015-8486 is considered to have a low severity level as it allows remote authenticated users to bypass access restrictions.
2
How do I fix CVE-2015-8486?
To address CVE-2015-8486, upgrade to a version of Cybozu Office that is later than 10.3.0.
3
Who is affected by CVE-2015-8486?
CVE-2015-8486 affects users of Cybozu Office versions 9.9.0 through 10.3.0.
4
What type of vulnerability is CVE-2015-8486?
CVE-2015-8486 is an access control vulnerability that allows unauthorized reading of report titles.
5
Is CVE-2015-8486 related to other vulnerabilities?
CVE-2015-8486 is a separate issue from CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.