VulnerabilityModified
CVE-2015-8485
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.
MEDIUM 5.4EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cybozu/office
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN48720230/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000023Vendor Advisory
- https://cs.cybozu.co.jp/2015/006077.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN48720230/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000023Vendor Advisory
- https://cs.cybozu.co.jp/2015/006077.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.