Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
BID:61359
Info
Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
| Bugtraq ID: | 61359 |
| Class: | Design Error |
| CVE: |
CVE-2013-3656 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2013 12:00AM |
| Updated: | Jul 16 2013 12:00AM |
| Credit: | Ooi Keita |
| Vulnerable: |
Cybozu Cybozu Office 9.1 |
| Not Vulnerable: | |
Discussion
Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
Cybozu Office is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the application. This may aid in further attacks.
Cybozu Office 9.1.0 and prior versions are vulnerable.
Cybozu Office is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the application. This may aid in further attacks.
Cybozu Office 9.1.0 and prior versions are vulnerable.
Exploit / POC
Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Cybozu Office CVE-2013-3656 Authentication Bypass Vulnerability
References:
References: