Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 9 |
CVE-ID | CVE-2020-5580 CVE-2020-5581 CVE-2020-5582 CVE-2020-5583 CVE-2020-5584 CVE-2020-5585 CVE-2020-5586 CVE-2020-5587 CVE-2020-5588 |
CWE-ID | CWE-200 CWE-22 CWE-264 CWE-79 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Cybozu Garoon Web applications / Other software |
Vendor | Cybozu |
Security Bulletin
This security bulletin contains information about 9 vulnerabilities.
EUVDB-ID: #VU29342
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-5580
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in Single sign-on settings. A remote authenticated attacker can view and/or alter Single sign-on settings.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29343
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-5581
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences on the portal. A remote authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29344
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5582
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can alter the data for the file attached to Report.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29345
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5583
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the Multi-Report. A remote authenticated attacker can obtain Multi-Report's data which the user has no viewing privileges of.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29346
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-5584
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29347
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5585
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in image asset functionality. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 5.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29348
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5586
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in system configuration. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.10.3 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29349
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-5587
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCybozu Garoon: 4.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29350
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5588
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences on the portal. A remote administrator can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsCybozu Garoon: 5.0.0 - 5.0.1
Fixed software versionsCPE2.3 External links
http://jvn.jp/en/jp/JVN55497111/index.html
http://cs.cybozu.co.jp/2020/007143.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?