VulnerabilityModified
CVE-2014-1993
The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
MEDIUM 4.0EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cybozu/garoon
- Source
- vultures@jpcert.or.jp
References
- http://cs.cybozu.co.jp/information/gr20140714up04.phpVendor Advisory
- http://jvn.jp/en/jp/JVN75990997/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000077Vendor Advisory
- http://cs.cybozu.co.jp/information/gr20140714up04.phpVendor Advisory
- http://jvn.jp/en/jp/JVN75990997/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000077Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.