CVE-2016-4869: Infoleak
Published Apr 17, 2017
·Updated
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
Affected Software
16 affected components
Cybozu Office=9.0
Cybozu Office=9.1.0
Cybozu Office=9.2.0
Cybozu Office=9.2.1
Cybozu Office=9.3.0
Cybozu Office=9.3.1
Cybozu Office=9.3.2
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Cybozu Office=10.4.0
Event History
Apr 17, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4869?
CVE-2016-4869 has a medium severity rating due to the risk of session information disclosure.
2
How do I fix CVE-2016-4869?
To fix CVE-2016-4869, update Cybozu Office to the latest version beyond 10.4.0.
3
Which versions are affected by CVE-2016-4869?
CVE-2016-4869 affects Cybozu Office versions from 9.0.0 to 10.4.0.
4
What type of vulnerability is CVE-2016-4869?
CVE-2016-4869 is a session fixation vulnerability that allows attackers to obtain session information.
5
Can CVE-2016-4869 be exploited remotely?
Yes, CVE-2016-4869 can be exploited remotely by attackers through specially crafted requests.