CVE-2016-4872: Infoleak
Published Apr 17, 2017
·Updated
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
Affected Software
16 affected components
Cybozu Office=9.0
Cybozu Office=9.1.0
Cybozu Office=9.2.0
Cybozu Office=9.2.1
Cybozu Office=9.3.0
Cybozu Office=9.3.1
Cybozu Office=9.3.2
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Cybozu Office=10.4.0
Event History
Apr 17, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4872?
CVE-2016-4872 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-4872?
To remediate CVE-2016-4872, upgrade to Cybozu Office version 10.5.0 or later.
3
What are the affected versions in CVE-2016-4872?
CVE-2016-4872 affects Cybozu Office versions 9.0.0 to 10.4.0.
4
What type of attacks can exploit CVE-2016-4872?
CVE-2016-4872 allows remote authenticated attackers to bypass access restrictions.
5
What information can be exposed due to CVE-2016-4872?
CVE-2016-4872 may lead to unauthorized visibility of project names in a breadcrumb trail.