CVE-2017-2091: Cybozu Garoon

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.

Affected products

  • Cybozu Garoon: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.1.0 only; version 3.1.1 only; …

Published 2017-04-28. Last modified 2026-06-17.