« Volver al listado

CVE-2015-2204

Estado: ModificadaAlta (7.5)—

Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-2204",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-01T17:29:01.167",
  "references": [
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/03/04/3",
      "tags": [
        "Issue Tracking",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/72889",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.launchpad.net/evergreen/+bug/1424755",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4",
      "tags": [
        "Issue Tracking",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/03/04/3",
      "tags": [
        "Issue Tracking",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72889",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.launchpad.net/evergreen/+bug/1424755",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided."
    },
    {
      "lang": "es",
      "value": "Evergreen en versiones anteriores a la 2.5.9, 2.6.x anteriores a la 2.6.7 y 2.7.x anteriores a la 2.7.4 permite que atacantes remotos omitan una restricción de acceso y obtengan información sensible sobre la configuración de las unidades organizativas aprovechándose del fallo open-ils.actor.ou_setting.ancestor_default para hacer cumplir view_perm cuando no se proporciona ningún token de autenticación."
    }
  ],
  "lastModified": "2026-06-17T00:23:45.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C011F2C-C3E1-45E5-B0EC-9062E9BC4D49",
              "versionEndExcluding": "2.5.9"
            },
            {
              "criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FF50689-92F5-49E6-9F28-D3D4EE097BC7",
              "versionEndExcluding": "2.6.7",
              "versionStartIncluding": "2.6.0"
            },
            {
              "criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6DCEDFF-4A88-4931-B550-E3E0E3E58C99",
              "versionEndExcluding": "2.7.4",
              "versionStartIncluding": "2.7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}