Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://support.cybozu.com/ja-jp/article/7893 | vendor advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2013-000125 | third party advisory |
http://jvn.jp/en/jp/JVN81706478/index.html | third party advisory |