PT-2018-4363 · Equinox · Evergreen

Jason Boyer

·

Publicado

2018-02-01

·

Atualizado

2018-02-15

·

CVE-2015-2203

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Evergreen versions 2.5.9, 2.6.7, 2.7.4
Description The issue allows remote authenticated users with STAFF LOGIN permission to obtain sensitive settings history information. This is achieved by leveraging the listing of open-ils.pcrud as a controller in the IDL.
Recommendations For versions 2.5.9, 2.6.7, and 2.7.4, consider restricting access to the open-ils.pcrud controller to prevent unauthorized users from obtaining sensitive settings history information. As a temporary workaround, restrict the STAFF LOGIN permission to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2203

Produtos afetados

Evergreen