PT-2018-5014 · Hewlett Packard · Hpe Helion Eucalyptus

Published

2018-02-15

·

Updated

2018-03-13

·

CVE-2016-8520

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Helion Eucalyptus versions 4.3.0 and earlier
Description The issue arises from incorrect permission checks for IAM users accessing versioned objects and ACLs. As a result, authenticated users with S3 permissions may also be able to access versioned data.
Recommendations For HPE Helion Eucalyptus versions 4.3.0 and earlier, consider restricting access to versioned objects and ACLs to prevent unauthorized data access until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8520

Affected Products

Hpe Helion Eucalyptus