First published: Wed Jan 09 2019(Updated: )
Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | >=3.0.0<=4.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16178 has a medium severity level due to its ability to allow unauthorized information access.
To fix CVE-2018-16178, update Cybozu Garoon to version 4.10.1 or later, which addresses this vulnerability.
CVE-2018-16178 is a security vulnerability that allows remote attackers to bypass access restrictions.
Users of Cybozu Garoon versions 3.0.0 to 4.10.0 are affected by CVE-2018-16178.
Attackers can exploit CVE-2018-16178 to view information that should only be accessible to authenticated users.