Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the affected product via the API.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://kb.cybozu.support/article/36118/ | vendor advisory |
https://jvn.jp/en/jp/JVN35649781/index.html | third party advisory |