CVE-2016-4867

MEDIUM

Cybozu Office - Information Disclosure

Title source: rule

Description

Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (17)

cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
... and 2 more

Timeline

Published Apr 17, 2017
Tracked Since Feb 18, 2026