Vulnerability Name:

CVE-2015-2687 (CCN-101839)

Assigned:2015-03-24
Published:2015-03-24
Updated:2017-08-24
Summary:OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
CVSS v3 Severity:4.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N)
1.4 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-284
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-2687

Source: CCN
Type: oss-security Mailing List, Tue, 24 Mar 2015 15:10:38 +1100
CVE request for OpenStack Compute (nova)

Source: CCN
Type: oss-security Mailing List, Tue, 24 Mar 2015 03:36:10 -0400 (EDT)
Re: CVE request for OpenStack Compute (nova)

Source: CCN
Type: IBM Security Bulletin T1022691
Openstack Nova vulnerability affects IBM Cloud Manager with OpenStack (CVE-2015-2687)

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20150324 Re: CVE request for OpenStack Compute (nova)

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20150325 Re: CVE request for OpenStack Compute (nova)

Source: BID
Type: Third Party Advisory, VDB Entry
77505

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory, VDB Entry
https://bugs.launchpad.net/nova/+bug/1419577

Source: CCN
Type: Red Hat Bugzilla – Bug 1205313
(CVE-2015-2687) CVE-2015-2687 openstack-nova: information leak when live-migration failed

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory, VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1205313

Source: XF
Type: UNKNOWN
openstack-nova-cve20152687-info-disc(101839)

Source: CONFIRM
Type: Third Party Advisory
https://review.openstack.org/#/c/338929/

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openstack:compute:2013.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2013.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2013.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2013.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2013.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:compute:2014.2.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openstack:nova:2013.2.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.trusty:def:20152687000
    V
    CVE-2015-2687 on Ubuntu 14.04 LTS (trusty) - low.
    2017-08-09
    oval:com.ubuntu.xenial:def:20152687000
    V
    CVE-2015-2687 on Ubuntu 16.04 LTS (xenial) - low.
    2017-08-09
    oval:com.ubuntu.xenial:def:201526870000000
    V
    CVE-2015-2687 on Ubuntu 16.04 LTS (xenial) - low.
    2017-08-09
    oval:com.ubuntu.precise:def:20152687000
    V
    CVE-2015-2687 on Ubuntu 12.04 LTS (precise) - low.
    2015-03-25
    BACK
    openstack compute 2013.2
    openstack compute 2013.2.1
    openstack compute 2013.2.2
    openstack compute 2013.2.3
    openstack compute 2013.2.4
    openstack compute 2014.1
    openstack compute 2014.1.1
    openstack compute 2014.1.2
    openstack compute 2014.1.3
    openstack compute 2014.1.4
    openstack compute 2014.1.5
    openstack compute 2014.2
    openstack compute 2014.2.1
    openstack compute 2014.2.2
    openstack compute 2014.2.3
    openstack compute 2014.2.4
    openstack nova 2013.2.3