CVE-2015-5649

EUVD-2015-5600
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
cybozugaroon
3.0.0
cybozugaroon
3.0.1
cybozugaroon
3.0.2
cybozugaroon
3.0.3
cybozugaroon
3.1.0
cybozugaroon
3.1.1
cybozugaroon
3.1.2
cybozugaroon
3.1.3
cybozugaroon
3.5.0
cybozugaroon
3.5.1
cybozugaroon
3.5.2
cybozugaroon
3.5.3
cybozugaroon
3.5.4
cybozugaroon
3.5.5
cybozugaroon
3.7:sp1
cybozugaroon
3.7:sp2
cybozugaroon
3.7:sp3
cybozugaroon
3.7.0
cybozugaroon
3.7.1
cybozugaroon
3.7.2
cybozugaroon
3.7.3
cybozugaroon
4.0.0
cybozugaroon
4.0.3
𝑥
= Vulnerable software versions