7.5
CVE-2015-2204
- EPSS 0.58%
- Veröffentlicht 01.02.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 02:26:59
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Evergreen-ils ≫ Evergreen Version < 2.5.9
Evergreen-ils ≫ Evergreen Version >= 2.6.0 < 2.6.7
Evergreen-ils ≫ Evergreen Version >= 2.7.0 < 2.7.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.68 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.