CVE-2015-1857: Infoleak
Published Apr 27, 2018
·Updated
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
Affected Software
1 affected component
linuxfoundation Opendaylight<0.2.4
Remediation
Patch Available
Patch Available
Event History
Apr 27, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1857?
CVE-2015-1857 has a medium severity rating as it allows remote attackers to access sensitive information.
2
How do I fix CVE-2015-1857?
To fix CVE-2015-1857, you should update to a version of OpenDaylight later than 0.2.4 that includes proper AAA restrictions.
3
What software versions are affected by CVE-2015-1857?
CVE-2015-1857 affects versions of OpenDaylight up to and including 0.2.4.
4
What kind of information can be exposed due to CVE-2015-1857?
CVE-2015-1857 allows attackers to obtain sensitive information due to missing access controls.
5
Is CVE-2015-1857 remote or local exploit?
CVE-2015-1857 is a remote vulnerability that can be exploited without physical access to the system.