Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
Advisories
Source ID Title
EUVD EUVD EUVD-2015-2310 Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T05:10:15.435Z

Reserved: 2015-03-03T00:00:00

Link: CVE-2015-2203

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-01T17:29:01.087

Modified: 2024-11-21T02:26:59.673

Link: CVE-2015-2203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses