CVE-2019-5943

MEDIUM

Cybozu Garoon 4.0.0-4.10.1 - Authenticated Access Restriction Bypass via Bulletin and Cabinet Applications

Title source: llm
STIX 2.1

Description

Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35486/

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
cybozu/garoon 4.0.0 - 4.10.1
Published May 17, 2019
Tracked Since Feb 18, 2026