CVE-2018-16169
Description
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cybozu Remote Service 3.0.0–3.1.0 allows authenticated attackers to upload and execute arbitrary Java code via the logo setting screen.
Vulnerability
Cybozu Remote Service versions 3.0.0 to 3.1.0 contain an improper input validation vulnerability in the logo setting screen, allowing remote authenticated attackers to upload arbitrary files, including Java code [1][2]. The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) [2].
Exploitation
An attacker must have valid credentials with at least basic privileges (PR:L) to access the management screen [1]. No user interaction is required (UI:N). The attack vector is network (AV:N) with low complexity (AC:L) [1][2]. The attacker can upload a malicious Java file through the logo setting screen, which is then executed on the server.
Impact
Successful exploitation leads to arbitrary Java code execution on the server, with high impact on confidentiality, integrity, and availability (CVSS v3 base score 8.8) [1][2]. The attacker can read, modify, or delete sensitive data and potentially take full control of the affected component.
Mitigation
Cybozu released version 3.1.1 which fixes this vulnerability [1]. Users should update to the latest version. No workarounds are mentioned in the references. The vulnerability is not listed in CISA KEV as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 3.0.0 to 3.1.0
- Cybozu, Inc./Cybozu Remote Servicev5Range: 3.0.0 to 3.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN23161885/index.htmlmitrethird-party-advisoryx_refsource_JVN
- kb.cybozu.support/article/34311/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.