CVE-2022-28713: Medium severity cybozu garoon vulnerability
Published Jul 4, 2022
·Updated
Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.
Affected Software
1 affected component
Cybozu Garoon>=4.10.0<=5.5.1
Event History
Jul 4, 2022
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-28713.
2
What is the severity level of CVE-2022-28713?
The severity level of CVE-2022-28713 is medium with a score of 5.3.
3
Which versions of Cybozu Garoon are affected by CVE-2022-28713?
Versions 4.10.0 to 5.5.1 of Cybozu Garoon are affected by CVE-2022-28713.
4
What is the impact of CVE-2022-28713?
CVE-2022-28713 allows a remote attacker to obtain some data of Facility Information without logging in to the product.
5
Are there any official sources for more information about CVE-2022-28713?
Yes, you can find more information about CVE-2022-28713 on the following pages: [Cybozu Security Advisory](https://cs.cybozu.co.jp/2022/007429.html) and [JVN](https://jvn.jp/en/jp/JVN73897863/index.html).