CVE-2014-0817

Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
cybozugaroon
2.0:sp1
cybozugaroon
2.0:sp2
cybozugaroon
2.0:sp3
cybozugaroon
2.0:sp4
cybozugaroon
2.0:sp5
cybozugaroon
2.0:sp6
cybozugaroon
2.0.0
cybozugaroon
2.0.1
cybozugaroon
2.0.2
cybozugaroon
2.0.3
cybozugaroon
2.0.4
cybozugaroon
2.0.5
cybozugaroon
2.0.6
cybozugaroon
2.1
cybozugaroon
2.1:sp1
cybozugaroon
2.1:sp2
cybozugaroon
2.1:sp3
cybozugaroon
2.1.0
cybozugaroon
2.1.1
cybozugaroon
2.1.2
cybozugaroon
2.1.3
cybozugaroon
2.5
cybozugaroon
2.5:sp1
cybozugaroon
2.5:sp2
cybozugaroon
2.5:sp3
cybozugaroon
2.5:sp4
cybozugaroon
2.5.0
cybozugaroon
2.5.1
cybozugaroon
2.5.2
cybozugaroon
2.5.3
cybozugaroon
2.5.4
cybozugaroon
3.0
cybozugaroon
3.0:sp1
cybozugaroon
3.0:sp2
cybozugaroon
3.0:sp3
cybozugaroon
3.1
cybozugaroon
3.1:sp1
cybozugaroon
3.1:sp2
cybozugaroon
3.1:sp3
cybozugaroon
3.5
cybozugaroon
3.5:sp1
cybozugaroon
3.5:sp2
cybozugaroon
3.5:sp3
cybozugaroon
3.5:sp4
cybozugaroon
3.5:sp5
cybozugaroon
3.5.3
cybozugaroon
3.7
cybozugaroon
3.7:sp1
cybozugaroon
3.7:sp2
cybozugaroon
3.7:sp3
𝑥
= Vulnerable software versions
Common Weakness Enumeration