First published: Mon Jul 11 2022(Updated: )
Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | >=4.0.0<=5.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30602 is a vulnerability that allows a remote authenticated attacker to alter file information and/or delete files in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1.
CVE-2022-30602 has a severity rating of 8.1, which is considered high.
Versions 4.0.0 to 5.9.1 of Cybozu Garoon are affected by CVE-2022-30602.
A remote authenticated attacker can exploit CVE-2022-30602 to bypass operation restrictions, allowing them to alter file information and/or delete files.
To mitigate CVE-2022-30602, it is recommended to update Cybozu Garoon to a version beyond 5.9.1 or apply the vendor-provided patches.