First published: Fri Jun 09 2017(Updated: )
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | =3.0.0 | |
Cybozu Garoon | =3.0.1 | |
Cybozu Garoon | =3.0.2 | |
Cybozu Garoon | =3.0.3 | |
Cybozu Garoon | =3.1.0 | |
Cybozu Garoon | =3.1.1 | |
Cybozu Garoon | =3.1.2 | |
Cybozu Garoon | =3.1.3 | |
Cybozu Garoon | =3.5.0 | |
Cybozu Garoon | =3.5.1 | |
Cybozu Garoon | =3.5.2 | |
Cybozu Garoon | =3.5.3 | |
Cybozu Garoon | =3.5.4 | |
Cybozu Garoon | =3.5.5 | |
Cybozu Garoon | =3.7.0 | |
Cybozu Garoon | =3.7.1 | |
Cybozu Garoon | =3.7.2 | |
Cybozu Garoon | =3.7.3 | |
Cybozu Garoon | =3.7.4 | |
Cybozu Garoon | =3.7.5 | |
Cybozu Garoon | =4.0.0 | |
Cybozu Garoon | =4.0.1 | |
Cybozu Garoon | =4.0.2 | |
Cybozu Garoon | =4.0.3 | |
Cybozu Garoon | =4.2.0 | |
Cybozu Garoon | =4.2.1 | |
Cybozu Garoon | =4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4910 is rated as a critical vulnerability that allows remote authenticated attackers to manipulate MultiReport filters.
To resolve CVE-2016-4910, upgrade your Cybozu Garoon installation to version 4.2.3 or later.
CVE-2016-4910 affects Cybozu Garoon versions from 3.0.0 to 4.2.2.
The vulnerability allows attackers to delete MultiReport filters belonging to other operational administrators, leading to unauthorized data manipulation.
Organizations using affected versions of Cybozu Garoon are at risk, particularly those with multiple operational administrators.