CVE-2019-6022: Path Traversal
Published Dec 26, 2019
·Updated
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function.
Affected Software
1 affected component
Cybozu Office>=10.0.0<=10.8.3
Event History
Dec 26, 2019
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6022?
The severity of CVE-2019-6022 is medium (6.5).
2
What is the affected software version range for CVE-2019-6022?
The affected software version range for CVE-2019-6022 is Cybozu Office 10.0.0 to 10.8.3.
3
How does the directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 work?
The directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function.
4
Is remote authentication required to exploit CVE-2019-6022?
Yes, remote authentication is required to exploit CVE-2019-6022.
5
Where can I find more information about CVE-2019-6022?
You can find more information about CVE-2019-6022 in the following references: [1] http://jvn.jp/en/jp/JVN79854355/index.html [2] https://kb.cybozu.support/article/36124