CVE-2015-2912
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
OrientDB-Server vulnerable to Cross-Site Request Forgery
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cret@cert.org — https://github.com/orientechnologies/orientdb/issues/4824
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.orientechnologies:orientdb-studio | <2.0.15 | 2.0.15 |
| Maven | com.orientechnologies:orientdb-studio | >=2.1.0,<2.1.1 | 2.1.1 |
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.