Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2015-10-08T20:00:00

Updated: 2024-08-06T06:59:03.498Z

Reserved: 2015-07-24T00:00:00

Link: CVE-2015-5649

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2015-10-08T20:59:00.097

Modified: 2015-10-09T17:28:24.837

Link: CVE-2015-5649

cve-icon Redhat

No data.