CVE-2016-4867: Infoleak
Published Apr 17, 2017
·Updated
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
Affected Software
16 affected components
Cybozu Office=9.0
Cybozu Office=9.1.0
Cybozu Office=9.2.0
Cybozu Office=9.2.1
Cybozu Office=9.3.0
Cybozu Office=9.3.1
Cybozu Office=9.3.2
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Cybozu Office=10.4.0
Event History
Apr 17, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4867?
CVE-2016-4867 has a medium severity rating due to its potential impact on project information exposure.
2
How do I fix CVE-2016-4867?
To fix CVE-2016-4867, upgrade to Cybozu Office version 10.5.0 or higher, which contains the necessary patch.
3
Who is affected by CVE-2016-4867?
CVE-2016-4867 affects users of Cybozu Office versions 9.0.0 to 10.4.0.
4
What type of vulnerability is CVE-2016-4867?
CVE-2016-4867 is an access control vulnerability that allows unauthorized viewing of project information.
5
Is CVE-2016-4867 exploitable remotely?
Yes, CVE-2016-4867 can be exploited by remote authenticated attackers.