Improper Authentication in Cybozu Garoon - CVE-2020-5563

 

Improper Authentication in Cybozu Garoon - CVE-2020-5563

Published: April 27, 2020


Vulnerability identifier: #VU27331
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5563
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in authentication process. A remote attacker with access to the API provided by the product can bypass authentication process and gain unauthorized access to sensitive information on the target systen.


Affected software

Cybozu Garoon

How to mitigate CVE-2020-5563

Install updates from vendor's website.

Cybozu Garoon - update to 5.0.0

External References

Related Security Bulletins