First published: Thu Aug 18 2022(Updated: )
Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Office | >=10.0.0<=10.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25986 is a browse restriction bypass vulnerability in the Scheduler of Cybozu Office versions 10.0.0 to 10.8.5.
CVE-2022-25986 allows a remote authenticated attacker to obtain the data of the Scheduler.
CVE-2022-25986 has a severity rating of 4.3, which is considered medium.
To fix the browse restriction bypass vulnerability in Cybozu Office, you should update to version 10.8.6 or later.
You can find more information about CVE-2022-25986 at the following references: - [Cybozu Security Advisory](https://cs.cybozu.co.jp/2022/007584.html) - [JVN](https://jvn.jp/en/jp/JVN20573662/index.html)