VulnerabilityModified
CVE-2018-0528
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.
MEDIUM 4.3EPSS 0.87%
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-287
- Affected
- cybozu/office
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN51737843/index.htmlThird Party Advisory
- https://support.cybozu.com/ja-jp/article/9812Third Party Advisory
- http://jvn.jp/en/jp/JVN51737843/index.htmlThird Party Advisory
- https://support.cybozu.com/ja-jp/article/9812Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.