CVE-2016-1218
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: vultures@jpcert.or.jp — https://support.cybozu.com/ja-jp/article/9414
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cybozu | garoon | {"endIncluding":"4.2.1"} | |
References
- http://jvn.jp/en/jp/JVN83568336/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000147.html
- http://www.securityfocus.com/bid/92600
- https://support.cybozu.com/ja-jp/article/9414
- http://jvn.jp/en/jp/JVN83568336/index.html
- http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000147.html
- http://www.securityfocus.com/bid/92600
- https://support.cybozu.com/ja-jp/article/9414
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.