« Volver al listado

CVE-2015-7862

Estado: ModificadaMedia (5)—

Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-7862",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-10-19T18:59:08.990",
  "references": [
    {
      "url": "http://www.securitytracker.com/id/1033862",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1033862",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Persistent Accelerite Radia Client Automation (anteriormente HP Client Automation) 7.9 hasta la versión 9.1 en versiones anteriores a 2015-02-19 no implementa adecuadamente la funcionalidad Role Based Access Control, lo que podría permitir a atacantes remotos modificar asignaciones de rol de una cuenta a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:33:17.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:accelerite:radia_client_automation:7.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9902293-6C38-4386-A8FA-E7631E0C11B2"
            },
            {
              "criteria": "cpe:2.3:a:accelerite:radia_client_automation:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7184E653-B224-4555-96E3-C1FCB82C344D"
            },
            {
              "criteria": "cpe:2.3:a:accelerite:radia_client_automation:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D0D12E5-2639-42D2-B477-90A06593568F"
            },
            {
              "criteria": "cpe:2.3:a:accelerite:radia_client_automation:9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "790AA8D9-FA95-4CBE-AC48-C82AD2D39C58"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}