5.8

CVE-2013-6006

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cybozu ≫ Garoon Version 3.5
Cybozu ≫ Garoon Version 3.5 Update sp1
Cybozu ≫ Garoon Version 3.5 Update sp2
Cybozu ≫ Garoon Version 3.5 Update sp3
Cybozu ≫ Garoon Version 3.5 Update sp4
Cybozu ≫ Garoon Version 3.5 Update sp5
Cybozu ≫ Garoon Version 3.5.3
Cybozu ≫ Garoon Version 3.7
Cybozu ≫ Garoon Version 3.7 Update sp1
Cybozu ≫ Garoon Version 3.7 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.99% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://jvn.jp/en/jp/JVN81706478/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2013-000125
https://support.cybozu.com/ja-jp/article/7893
Vendor Advisory