Published:2013/07/16  Last Updated:2013/07/17

JVN#19491840
Cybozu Office session management vulnerability

Overview

Cybozu Office contains a vulnerability in session management.

Products Affected

  • Cybozu Office 9.1.0 and earlier

Description

Cybozu Office is a groupware. Cybozu Office contains a vulnerability in session management.

Impact

A third-party that obtains the URL for a login may impersonate a user and access the product. As a result information may be altered or disclosed.

Solution

Update the software
Update to the latest version according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2013.07.16

Measures Conditions Severity
Access Required can be attacked over the Internet using packets
  • High
Authentication anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required the vulnerability can be exploited without an honest user taking any action
  • High
Exploit Complexity expertise and/or luck required (guessing correctly in medium-sized space, kernel expertise)
  • Low-Mid

Description of each analysis measures

Credit

Ooi Keita reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2013-3656
JVN iPedia JVNDB-2013-000069

Update History

2013/07/17
Information under the section "Vendor Status" was modified.