SB2017042015 - Multiple vulnerabilities in Cybozu Mailwise
Published: April 20, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2016-4841)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
2) Information disclosure (CVE-ID: CVE-2016-4842)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
3) Information disclosure (CVE-ID: CVE-2016-4843)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.
4) Information disclosure (CVE-ID: CVE-2016-4844)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
Remediation
Install update from vendor's website.
References
- http://jvn.jp/en/jp/JVN01353821/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000135.html
- http://www.securityfocus.com/bid/92459
- https://support.cybozu.com/ja-jp/article/9607
- http://jvn.jp/en/jp/JVN02576342/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000136.html
- http://www.securityfocus.com/bid/92460
- https://support.cybozu.com/ja-jp/article/9606
- http://jvn.jp/en/jp/JVN03052683/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000137.html
- http://www.securityfocus.com/bid/92461
- https://support.cybozu.com/ja-jp/article/9654
- http://jvn.jp/en/jp/JVN04125292/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000138.html
- http://www.securityfocus.com/bid/92462
- https://support.cybozu.com/ja-jp/article/9605