CVE-2017-2094: Cybozu Garoon

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

Affected products

  • Cybozu Garoon: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.1.0 only; version 3.1.1 only; …

Published 2017-04-28. Last modified 2026-06-17.