VulnerabilityModified
CVE-2010-2029
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
MEDIUM 5.8EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cybozu/cybozu office · cybozu/cybozu dotsales
- Source
- cve@mitre.org
References
- http://cybozu.co.jp/products/dl/notice/detail/0034.html
- http://jvn.jp/en/jp/JVN87730223/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html
- http://secunia.com/advisories/39508Vendor Advisory
- http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html
- http://www.osvdb.org/63933
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57976
- http://cybozu.co.jp/products/dl/notice/detail/0034.html
- http://jvn.jp/en/jp/JVN87730223/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html
- http://secunia.com/advisories/39508Vendor Advisory
- http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html
- http://www.osvdb.org/63933
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57976
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.