CVE Vulnerabilities

CVE-2016-1189

Published: Jun 25, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
GaroonCybozu3.1.0 (including)3.1.0 (including)
GaroonCybozu3.1.1 (including)3.1.1 (including)
GaroonCybozu3.1.2 (including)3.1.2 (including)
GaroonCybozu3.1.3 (including)3.1.3 (including)
GaroonCybozu3.5.0 (including)3.5.0 (including)
GaroonCybozu3.5.1 (including)3.5.1 (including)
GaroonCybozu3.5.2 (including)3.5.2 (including)
GaroonCybozu3.5.3 (including)3.5.3 (including)
GaroonCybozu3.5.4 (including)3.5.4 (including)
GaroonCybozu3.5.5 (including)3.5.5 (including)
GaroonCybozu3.7.0 (including)3.7.0 (including)
GaroonCybozu3.7.1 (including)3.7.1 (including)
GaroonCybozu3.7.2 (including)3.7.2 (including)
GaroonCybozu3.7.3 (including)3.7.3 (including)
GaroonCybozu3.7.4 (including)3.7.4 (including)
GaroonCybozu3.7.5 (including)3.7.5 (including)
GaroonCybozu4.0.0 (including)4.0.0 (including)
GaroonCybozu4.0.1 (including)4.0.1 (including)
GaroonCybozu4.0.2 (including)4.0.2 (including)
GaroonCybozu4.0.3 (including)4.0.3 (including)
GaroonCybozu4.2.0 (including)4.2.0 (including)

References