{"api_version":"1","generated_at":"2026-07-24T20:36:02+00:00","cve":"CVE-2021-20625","urls":{"html":"https://cve.report/CVE-2021-20625","api":"https://cve.report/api/cve/CVE-2021-20625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-20625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-20625"},"summary":{"title":"CVE-2021-20625","description":"Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2021-03-18 01:15:00","updated_at":"2022-07-12 17:42:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://kb.cybozu.support/article/36874/","name":"https://kb.cybozu.support/article/36874/","refsource":"MISC","tags":[],"title":"不具合情報公開サイト","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://jvn.jp/en/jp/JVN45797538/index.html","name":"https://jvn.jp/en/jp/JVN45797538/index.html","refsource":"MISC","tags":[],"title":"JVN#45797538: Multiple vulnerabilities in Cybozu Office","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-20625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"20625","vulnerable":"1","versionEndIncluding":"10.8.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cybozu","cpe5":"office","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-20625","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Cybozu, Inc.","product":{"product_data":[{"product_name":"Cybozu Office","version":{"version_data":[{"version_value":"10.0.0 to 10.8.4"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control"}]}]},"references":{"reference_data":[{"url":"https://jvn.jp/en/jp/JVN45797538/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN45797538/index.html"},{"url":"https://kb.cybozu.support/article/36874/","refsource":"MISC","name":"https://kb.cybozu.support/article/36874/"}]},"description":{"description_data":[{"lang":"eng","value":"Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors."}]}},"nvd":{"publishedDate":"2021-03-18 01:15:00","lastModifiedDate":"2022-07-12 17:42:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"20625","Ordinal":"194670","Title":"CVE-2021-20625","CVE":"CVE-2021-20625","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"20625","Ordinal":"1","NoteData":"Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"20625","Ordinal":"2","NoteData":"2021-03-17","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"20625","Ordinal":"3","NoteData":"2021-03-17","Type":"Other","Title":"Modified"}]}}}