← Back

CVE-2015-2204

nvd nist
Published: Feb 1, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.

Affected (3)

1 product
Evergreen
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Evergreen Ils
Before 2.5.9
From 2.6.0 to 2.6.7
From 2.7.0 to 2.7.4

References (16)

Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingPatchRelease Notes
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.