← Back

CVE-2015-6861

nvd nist
Published: Jan 5, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.

Affected (11)

1 product
Eucalyptus
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Eucalyptus
Version 3.4.0
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.2.0

Related CWEs

References (4)

Timeline

No history available yet.