CVE-2016-1190: Medium severity cybozu garoon vulnerability
Published Jun 25, 2016
·Updated
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.
Affected Software
21 affected components
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Event History
Jun 25, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1190?
CVE-2016-1190 is classified with a specific severity level that indicates it allows bypassing restrictions on MultiReport reading.
2
How do I fix CVE-2016-1190?
To fix CVE-2016-1190, it's recommended to update to the latest version of Cybozu Garoon that addresses this vulnerability.
3
Which versions of Cybozu Garoon are affected by CVE-2016-1190?
CVE-2016-1190 affects Cybozu Garoon versions from 3.1 to 4.2.
4
Can CVE-2016-1190 be exploited by unauthenticated users?
No, CVE-2016-1190 can only be exploited by remote authenticated users.
5
What should organizations do to mitigate the risks of CVE-2016-1190?
Organizations should audit their Cybozu Garoon installations and ensure they are running a patched version to mitigate the risks associated with CVE-2016-1190.