CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.
CVE
CVE-2015-2204
Severity
HIGH
CVSS
7.5
EPSS
3.11%
Original NVD Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Related CVEs
Other vulnerabilities affecting the same vendor(s)