First published: Fri Oct 23 2015(Updated: )
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | <=5.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7031 is classified as a medium severity vulnerability.
CVE-2015-7031 allows remote attackers to bypass intended access restrictions due to an omitted HTTP header configuration.
CVE-2015-7031 affects Apple OS X Server versions before 5.0.15.
To mitigate CVE-2015-7031, upgrade to Apple OS X Server version 5.0.15 or later.
Yes, CVE-2015-7031 can be exploited by remote attackers.