Access Restriction Bypass in Evergreen by Equinox Software
CVE-2015-2204
7.5HIGH
What is CVE-2015-2204?
Evergreen versions prior to 2.5.9, 2.6.7, and 2.7.4 are susceptible to an access restriction bypass vulnerability. This flaw allows remote attackers to exploit the open-ils.actor.ou_setting.ancestor_default functionality, which fails to enforce view permissions when no authentication token is present. Consequently, sensitive organizational unit settings can be disclosed, posing a risk to data privacy and integrity.
