CVE-2021-20801: XEE
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20801?
The severity of CVE-2021-20801 is medium, with a severity value of 6.5.
How does CVE-2021-20801 affect Cybozu Remote Service Manager?
CVE-2021-20801 affects Cybozu Remote Service Manager versions 3.1.8 to 3.1.9.
What is the vulnerability in CVE-2021-20801?
CVE-2021-20801 is a vulnerability that allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain stored information in Cybozu Remote Service Manager.
Which web browser is affected by CVE-2021-20801?
CVE-2021-20801 affects only Mozilla Firefox when using Cybozu Remote Service Manager.
How can I fix CVE-2021-20801 in Cybozu Remote Service Manager?
To fix CVE-2021-20801, upgrade Cybozu Remote Service Manager to a version higher than 3.1.9.