« Back to list

CVE-2015-5502

Status: ModifiedHigh (7.5)—

The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2015-5502",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-08-18T18:00:06.737",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/74867",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2495895",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2495903",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/74867",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2495895",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2495903",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el módulo Storage API 7.x-1.x en versiones anteriores a 7.x-1.8 para Drupal, no restringe adecuadamente el acceso a campos Storage API adjuntos a entidades que no son nodos, lo que permite a atacantes remotos tener un impacto no especificado a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-17T00:29:14.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F53BD86D-1D12-483D-8425-3186AF742319"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F477505A-B044-49B2-906E-9E60F3401638"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "431F0BCF-BF18-47D6-B2AB-C0B6BF76C2B1"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.3:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "381362AD-2BFF-4E72-9C3D-2C2546A3A5BC"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.4:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E70C665-BBF9-4A90-9272-AF3C80881BB2"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.5:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D3BEF4E-B13E-465F-AFC6-EA8D07A72803"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.6:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9ADC64DB-1C19-4B98-9EC3-667627D975F6"
            },
            {
              "criteria": "cpe:2.3:a:storage_api_project:storage_api:7.x-1.7:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06A1BE72-41F1-492E-9404-8A25967B5306"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}