[Japanese]
|
JVNDB-2014-000023
|
Cybozu Garoon vulnerable to directory traversal
|
Cybozu Garoon contains a directory traversal vulnerability.
Cybozu Garoon provided by Cybozu, Inc. is a groupware. Cybozu Garoon contains a directory traversal vulnerability in the process of downloading files.
|
CVSS V2 Severity: Base Metrics 3.5 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
Cybozu, Inc.
- Cybozu Garoon 2.5.4 and earlier
- Cybozu Garoon 3.7 Service Pack 3 and earlier
|
|
A user who can log in to the product may obtain files on the server.
|
For Cybozu Garoon 3.7:
[Apply the Patch]
Apply the appropriate patch according to the information provided by the developer.
For Cybozu Garoon 3.5 and earlier and Cybozu Garoon 2.5.4 and earlier:
[Update the Software and apply the patch]
Update to the latest version, and then apply the appropriate patch according to the information provided by the developer.
|
Cybozu, Inc.
|
- Path Traversal(CWE-22) [IPA Evaluation]
|
- CVE-2014-0820
|
- JVN : JVN#26393529
- National Vulnerability Database (NVD) : CVE-2014-0820
|
- [2014/02/26]
Web page was published
[2014/03/03]
References : Content was added
|