CVE-2015-2204
Estado: ModificadaAlta (7.5)—
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.11%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307
- http://www.openwall.com/lists/oss-security/2015/03/04/3
- http://www.securityfocus.com/bid/72889
- https://bugs.launchpad.net/evergreen/+bug/1424755
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307
- http://www.openwall.com/lists/oss-security/2015/03/04/3
- http://www.securityfocus.com/bid/72889
- https://bugs.launchpad.net/evergreen/+bug/1424755
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-2204",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-02-01T17:29:01.167",
"references": [
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "cve@mitre.org"
},
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "cve@mitre.org"
},
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "cve@mitre.org"
},
{
"url": "http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/",
"tags": [
"Issue Tracking",
"Patch",
"Release Notes"
],
"source": "cve@mitre.org"
},
{
"url": "http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/03/04/3",
"tags": [
"Issue Tracking",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/72889",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugs.launchpad.net/evergreen/+bug/1424755",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4",
"tags": [
"Issue Tracking",
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/",
"tags": [
"Issue Tracking",
"Patch",
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/03/04/3",
"tags": [
"Issue Tracking",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/72889",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/evergreen/+bug/1424755",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided."
},
{
"lang": "es",
"value": "Evergreen en versiones anteriores a la 2.5.9, 2.6.x anteriores a la 2.6.7 y 2.7.x anteriores a la 2.7.4 permite que atacantes remotos omitan una restricción de acceso y obtengan información sensible sobre la configuración de las unidades organizativas aprovechándose del fallo open-ils.actor.ou_setting.ancestor_default para hacer cumplir view_perm cuando no se proporciona ningún token de autenticación."
}
],
"lastModified": "2026-06-17T00:23:45.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C011F2C-C3E1-45E5-B0EC-9062E9BC4D49",
"versionEndExcluding": "2.5.9"
},
{
"criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FF50689-92F5-49E6-9F28-D3D4EE097BC7",
"versionEndExcluding": "2.6.7",
"versionStartIncluding": "2.6.0"
},
{
"criteria": "cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6DCEDFF-4A88-4931-B550-E3E0E3E58C99",
"versionEndExcluding": "2.7.4",
"versionStartIncluding": "2.7.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}