VYPR

Garoon

by Cybozu

CVEs (201)

  • CVE-2021-20756MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.

  • CVE-2021-20755MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.

  • CVE-2021-20754MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

  • CVE-2020-5582MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors.

  • CVE-2020-5566MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'.

  • CVE-2020-5565MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.

  • CVE-2019-5977MedSep 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.

  • CVE-2019-5944MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.

  • CVE-2019-5943MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'.

  • CVE-2019-5942MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.

  • CVE-2019-5941MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the Report without access privileges via the application 'Multi Report'.

  • CVE-2019-5935MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.

  • CVE-2019-5933MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.

  • CVE-2019-5930MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'.

  • CVE-2018-0550MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.

  • CVE-2018-0548MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.

  • CVE-2018-0531MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.

  • CVE-2017-2258MedAug 29, 2017
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

  • CVE-2016-7801MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.

  • CVE-2016-4910MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.

Page 7 of 11