CVE-2016-1185: Infoleak
Published Apr 25, 2016
·Updated
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.
Affected Software
6 affected components
Cybozu Kintone Android=1.0.0
Cybozu Kintone Android=1.0.1
Cybozu Kintone Android=1.0.2
Cybozu Kintone Android=1.0.3
Cybozu Kintone Android=1.0.4
Cybozu Kintone Android=1.0.5
Event History
Apr 25, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1185?
CVE-2016-1185 has been classified with a medium severity level due to its potential to expose an authentication token.
2
How do I fix CVE-2016-1185?
To mitigate CVE-2016-1185, update the Cybozu Kintone mobile application to version 1.0.6 or later.
3
What systems are affected by CVE-2016-1185?
CVE-2016-1185 affects versions 1.0.0 to 1.0.5 of the Cybozu Kintone mobile application for Android.
4
What kind of vulnerability is CVE-2016-1185?
CVE-2016-1185 is an information disclosure vulnerability that can allow attackers to discover an authentication token.
5
Who are likely targets of CVE-2016-1185?
Users of the Cybozu Kintone mobile application prior to version 1.0.6 on Android are the likely targets of CVE-2016-1185.