CVE-2017-2109: Infoleak
Published Apr 28, 2017
·Updated
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.
Affected Software
3 affected components
Cybozu Kunai Android=3.0.4
Cybozu Kunai Android=3.0.5
Cybozu Kunai Android=3.0.5.1
Event History
Apr 28, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2109?
CVE-2017-2109 is classified as a medium severity vulnerability that allows remote attackers to obtain sensitive log information.
2
How do I fix CVE-2017-2109?
To fix CVE-2017-2109, update to Cybozu KUNAI version 3.0.5.2 or later to mitigate the vulnerability.
3
What impact does CVE-2017-2109 have on users?
CVE-2017-2109 can expose user log information, potentially leading to unauthorized access or data leakage.
4
Which versions of Cybozu KUNAI are affected by CVE-2017-2109?
CVE-2017-2109 affects Cybozu KUNAI versions 3.0.4 to 3.0.5.1 on Android.
5
Is CVE-2017-2109 exploitable via user interaction?
Yes, CVE-2017-2109 can be exploited through a malicious Android application requiring user installation.