SB2021031506 - Multiple vulnerabilities in Cybozu Office
Published: March 15, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20624)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Scheduler. A remote authenticated attacker can alter the data of Scheduler without appropriate privileges.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20625)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Bulletin Board. A remote authenticated attacker can alter the data of Bulletin Board without appropriate privileges.
3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20626)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Workflow. A remote authenticated attacker can alter the data of Workflow without appropriate privileges.
4) Cross-site scripting (CVE-ID: CVE-2021-20627)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Address Book. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
5) Cross-site scripting (CVE-ID: CVE-2021-20628)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Address Book. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
6) Cross-site scripting (CVE-ID: CVE-2021-20629)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in E-mail. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
7) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20630)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Phone Messages. A remote authenticated attacker can obtain the data of Phone Messages without the viewing privileges.
8) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20631)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Custom App. A remote authenticated attacker can obtain the data of Bulletin Board without the viewing privileges.
9) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20632)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Bulletin Board. A remote authenticated attacker can obtain the data of Bulletin Board without the viewing privileges.
10) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20633)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Cabine. A remote authenticated attacker can obtain the data of Cabinet without the viewing privileges.
11) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20634)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Custom App. A remote authenticated attacker can obtain the data of Custom App without the viewing privileges.
Remediation
Install update from vendor's website.