CVE-2016-1189: High severity cybozu garoon vulnerability
Published Jun 25, 2016
·Updated
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors.
Affected Software
21 affected components
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Event History
Jun 25, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1189?
CVE-2016-1189 has a medium severity rating due to its potential for unauthorized access and data manipulation by authenticated users.
2
How do I fix CVE-2016-1189?
To fix CVE-2016-1189, you should upgrade to Cybozu Garoon version 4.2.1 or later.
3
Which versions of Cybozu Garoon are affected by CVE-2016-1189?
CVE-2016-1189 affects Cybozu Garoon versions 3.x and 4.x prior to version 4.2.1.
4
Can CVE-2016-1189 be exploited by remote attackers?
CVE-2016-1189 can only be exploited by remote authenticated users, not unauthenticated attackers.
5
What kind of restrictions can be bypassed due to CVE-2016-1189?
CVE-2016-1189 allows remote authenticated users to bypass restrictions on reading, creating, or modifying a portlet.