CVE-2016-1196: Infoleak
Published Jun 19, 2016
·Updated
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.
Affected Software
25 affected components
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Remediation
Patch Available
Event History
Jun 19, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1196?
CVE-2016-1196 has been assigned a medium severity rating due to its nature of allowing unauthorized access to sensitive data.
2
How do I fix CVE-2016-1196?
To remediate CVE-2016-1196, upgrade to Cybozu Garoon version 4.2.1 or later.
3
Which versions of Cybozu Garoon are affected by CVE-2016-1196?
CVE-2016-1196 affects Cybozu Garoon versions 3.x and 4.x prior to 4.2.1.
4
What kind of data can be exposed due to CVE-2016-1196?
CVE-2016-1196 allows remote authenticated users to bypass access restrictions and access sensitive Address Book information.
5
Is CVE-2016-1196 related to any other vulnerabilities?
Yes, CVE-2016-1196 is a different vulnerability than CVE-2015-7776 which also affected Cybozu Garoon.