CVE-2015-2204
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Affected (3)
Products: Evergreen Ils: Evergreen
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.9 |
References (16)
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingPatchRelease Notes
Source: cve@mitre.org
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Timeline
No history available yet.