CVE-2022-28692: Input Validation
Published Jul 4, 2022
·Updated
Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Scheduler.
Affected Software
1 affected component
Cybozu Garoon>=4.0.0<=5.5.1
Event History
Jul 4, 2022
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the improper input validation vulnerability in Cybozu Garoon?
The vulnerability ID is CVE-2022-28692.
2
What is the affected software version range for the Cybozu Garoon vulnerability?
The vulnerability affects Cybozu Garoon versions 4.0.0 to 5.5.1.
3
How can an attacker exploit the improper input validation vulnerability in Scheduler?
An attacker with remote authenticated access can use this vulnerability to alter Scheduler data.
4
What is the severity rating for the Cybozu Garoon vulnerability?
The severity rating is medium with a CVSS score of 4.3.
5
Are there any official references for the Cybozu Garoon vulnerability?
Yes, you can find more information about the vulnerability at the following references: [Reference 1](https://cs.cybozu.co.jp/2022/007429.html), [Reference 2](https://jvn.jp/en/jp/JVN73897863/index.html).