CVE-2017-2095: Cybozu Garoon

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.

Affected products

  • Cybozu Garoon: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.1.0 only; version 3.1.1 only; …

Published 2017-04-28. Last modified 2026-06-17.