CVE-2016-4874: Low severity cybozu office vulnerability
Published Apr 17, 2017
·Updated
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
Affected Software
16 affected components
Cybozu Office=9.0
Cybozu Office=9.1.0
Cybozu Office=9.2.0
Cybozu Office=9.2.1
Cybozu Office=9.3.0
Cybozu Office=9.3.1
Cybozu Office=9.3.2
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Cybozu Office=10.4.0
Event History
Apr 17, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4874?
CVE-2016-4874 has a medium severity rating due to its potential for reflected file download attacks.
2
How does CVE-2016-4874 allow an attack?
CVE-2016-4874 enables attackers to trick users into downloading files disguised as legitimate content.
3
What versions of Cybozu Office are affected by CVE-2016-4874?
CVE-2016-4874 affects Cybozu Office versions 9.0.0 through 10.4.0.
4
How can I mitigate CVE-2016-4874?
To mitigate CVE-2016-4874, update your Cybozu Office software to the latest version.
5
Is there a patch available for CVE-2016-4874?
Yes, a patch for CVE-2016-4874 is available in the latest updates for affected Cybozu Office versions.