CVE-2019-5944

MEDIUM

Cybozu Garoon 4.0.0-4.10.1 - Authenticated Access Restriction Bypass in Address Application

Title source: llm
STIX 2.1

Description

Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35487/

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (1)
cybozu/garoon 4.0.0 - 4.10.1
Published May 17, 2019
Tracked Since Feb 18, 2026