CVE-2018-16169: Malicious File Upload
Published Jan 9, 2019
·Updated
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
Affected Software
1 affected component
Cybozu Remote Service Manager>=3.0.0<=3.1.0
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-16169?
CVE-2018-16169 is a vulnerability in Cybozu Remote Service 3.0.0 to 3.1.0 that allows remote authenticated attackers to upload and execute Java code file on the server.
2
How severe is CVE-2018-16169?
CVE-2018-16169 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2018-16169?
Cybozu Remote Service Manager versions 3.0.0 to 3.1.0 are affected by CVE-2018-16169.
4
How can I fix CVE-2018-16169?
To fix CVE-2018-16169, update Cybozu Remote Service Manager to a version higher than 3.1.0.
5
Where can I find more information about CVE-2018-16169?
More information about CVE-2018-16169 can be found at the following references: [Reference 1](https://jvn.jp/en/jp/JVN23161885/index.html) and [Reference 2](https://kb.cybozu.support/article/34311/).