Vulnerability Description
HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eucalyptus | Eucalyptus | 3.4.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/79650
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cVendor Advisory
- http://www.securityfocus.com/bid/79650
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cVendor Advisory
FAQ
What is CVE-2015-6861?
CVE-2015-6861 is a vulnerability with a CVSS score of 7.5 (HIGH). HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's a...
How severe is CVE-2015-6861?
CVE-2015-6861 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6861?
Check the references section above for vendor advisories and patch information. Affected products include: Eucalyptus Eucalyptus.