CVE-2016-4873: Medium severity cybozu office vulnerability
Published Apr 17, 2017
·Updated
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
Affected Software
16 affected components
Cybozu Office=9.0
Cybozu Office=9.1.0
Cybozu Office=9.2.0
Cybozu Office=9.2.1
Cybozu Office=9.3.0
Cybozu Office=9.3.1
Cybozu Office=9.3.2
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Cybozu Office=10.4.0
Event History
Apr 17, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4873?
CVE-2016-4873 is rated as a medium-level vulnerability.
2
How do I fix CVE-2016-4873?
To fix CVE-2016-4873, you should upgrade to a version of Cybozu Office that is newer than 10.4.0.
3
What types of attacks can exploit CVE-2016-4873?
CVE-2016-4873 can be exploited by remote authenticated attackers to perform unintended operations.
4
Which versions of Cybozu Office are affected by CVE-2016-4873?
CVE-2016-4873 affects Cybozu Office versions 9.0.0 through 10.4.0.
5
Is it safe to use Cybozu Office 10.4.0 with CVE-2016-4873 vulnerability?
No, using Cybozu Office version 10.4.0 is not safe as it is still vulnerable to CVE-2016-4873.