Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain customapp information via unspecified vectors.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Office | Cybozu | 10.0.0 (including) | 10.0.0 (including) |
Office | Cybozu | 10.0.1 (including) | 10.0.1 (including) |
Office | Cybozu | 10.0.2 (including) | 10.0.2 (including) |
Office | Cybozu | 10.1.0 (including) | 10.1.0 (including) |
Office | Cybozu | 10.1.2 (including) | 10.1.2 (including) |
Office | Cybozu | 10.2.0 (including) | 10.2.0 (including) |
Office | Cybozu | 10.3.0 (including) | 10.3.0 (including) |
Office | Cybozu | 10.4.0 (including) | 10.4.0 (including) |
Office | Cybozu | 10.5.0 (including) | 10.5.0 (including) |