Vulnerability identifier: #VU39163
Vulnerability risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2016-4842
CWE-ID:
CWE-200
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Mailwise
Mobile applications /
Apps for mobile phones
Vendor: Cybozu
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Mailwise: 5.0.0 - 5.3.2
External links
https://jvn.jp/en/jp/JVN02576342/index.html
https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000136.html
https://www.securityfocus.com/bid/92460
https://support.cybozu.com/ja-jp/article/9606
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.