[Japanese]

JVNDB-2014-000010

Multiple SQL injection vulnerabilities in Cybozu Garoon

Overview

Cybozu Garoon contains multiple SQL injection vulnerabilities.

Cybozu Garoon contains issues in the process of page navigation link and input through API, which may result in SQL injection.

Note that this vulnerability is different from JVN#60997973.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 6.5 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial
Affected Products


Cybozu, Inc.
  • Cybozu Garoon version 3.7 Service Pack 2 and earlier

Impact

A user who can log in to the system may obtain or alter data in the database.
Solution

[Apply the Patch]
Apply the appropriate patch according to the information provided by the developer.
Vendor Information

Cybozu, Inc.
CWE (What is CWE?)

  1. SQL Injection(CWE-89) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2013-6930
  2. CVE-2013-6931
References

  1. JVN : JVN#91153528
  2. National Vulnerability Database (NVD) : CVE-2013-6930
  3. National Vulnerability Database (NVD) : CVE-2013-6931
Revision History

  • [2014/01/28]
      Web page was published
    [2014/01/30]
      References : Contents were added