VYPR
Unrated severityNVD Advisory· Published Jan 9, 2019· Updated Aug 5, 2024

CVE-2018-16169

CVE-2018-16169

Description

Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cybozu Remote Service 3.0.0–3.1.0 allows authenticated attackers to upload and execute arbitrary Java code via the logo setting screen.

Vulnerability

Cybozu Remote Service versions 3.0.0 to 3.1.0 contain an improper input validation vulnerability in the logo setting screen, allowing remote authenticated attackers to upload arbitrary files, including Java code [1][2]. The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) [2].

Exploitation

An attacker must have valid credentials with at least basic privileges (PR:L) to access the management screen [1]. No user interaction is required (UI:N). The attack vector is network (AV:N) with low complexity (AC:L) [1][2]. The attacker can upload a malicious Java file through the logo setting screen, which is then executed on the server.

Impact

Successful exploitation leads to arbitrary Java code execution on the server, with high impact on confidentiality, integrity, and availability (CVSS v3 base score 8.8) [1][2]. The attacker can read, modify, or delete sensitive data and potentially take full control of the affected component.

Mitigation

Cybozu released version 3.1.1 which fixes this vulnerability [1]. Users should update to the latest version. No workarounds are mentioned in the references. The vulnerability is not listed in CISA KEV as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.