CVE-2017-2145: Medium severity cybozu garoon vulnerability
Published Jul 7, 2017
·Updated
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
Affected Software
9 affected components
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Cybozu Garoon=4.2.3
Cybozu Garoon=4.2.4
Event History
Jul 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2145?
CVE-2017-2145 has been classified with a medium severity level due to its session fixation vulnerability.
2
How do I fix CVE-2017-2145?
To fix CVE-2017-2145, upgrade Cybozu Garoon from versions 4.0.0 to 4.2.4 to a patched version.
3
What software is affected by CVE-2017-2145?
CVE-2017-2145 affects Cybozu Garoon versions 4.0.0 to 4.2.4.
4
Can CVE-2017-2145 lead to unauthorized access?
Yes, CVE-2017-2145 allows remote attackers to perform arbitrary operations, potentially leading to unauthorized access.
5
What types of attacks can exploit CVE-2017-2145?
CVE-2017-2145 can be exploited through session fixation, allowing attackers to hijack or control user sessions.