CVE-2017-2094: Medium severity cybozu garoon vulnerability
Published Apr 28, 2017
·Updated
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.
Affected Software
28 affected components
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Cybozu Garoon=4.2.3
Event History
Apr 28, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2094?
CVE-2017-2094 is considered a medium severity vulnerability, affecting the access restrictions in Cybozu Garoon.
2
How do I fix CVE-2017-2094?
To fix CVE-2017-2094, upgrade Cybozu Garoon to version 4.2.4 or later, as this version addresses the vulnerability.
3
What versions of Cybozu Garoon are affected by CVE-2017-2094?
CVE-2017-2094 affects Cybozu Garoon versions from 3.0.0 to 4.2.3.
4
What impact does CVE-2017-2094 have?
CVE-2017-2094 allows remote authenticated attackers to bypass access restrictions, potentially altering or deleting information.
5
Who can exploit CVE-2017-2094?
CVE-2017-2094 can be exploited by remote authenticated attackers with access to the Workflow and MultiReport functionalities.