Vulnerability Description
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cybozu | Cybozu Office | <= 9.1.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN19491840/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000069
- http://products.cybozu.co.jp/office/ver9/download/update/fix910.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85894
- http://jvn.jp/en/jp/JVN19491840/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000069
- http://products.cybozu.co.jp/office/ver9/download/update/fix910.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85894
FAQ
What is CVE-2013-3656?
CVE-2013-3656 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
How severe is CVE-2013-3656?
CVE-2013-3656 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3656?
Check the references section above for vendor advisories and patch information. Affected products include: Cybozu Cybozu Office.