CVE-2015-2342
VMware vCenter Server JMX RMI Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
El servicio JMX RMI en Vmware vCenter Server 5.0 en versiones anteriores a u3e, 5.1 en versiones anteriores a u3b, 5.5 en versiones anteriores a u3 y 6.0 en versiones anterioes a u1 no restringe el registro de Mbeans, lo que permite a atacantes remotos ejecutar código arbitrario a través del protocolo RMI.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of VMware vCenter Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled mbeans. This vulnerability can be leveraged by an attacker to gain remote code execution under the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-02-17 First Exploit
- 2015-03-18 CVE Reserved
- 2015-10-02 CVE Published
- 2024-08-06 CVE Updated
- 2024-11-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (9)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/36101 | 2015-02-17 |
URL | Date | SRC |
---|---|---|
http://www.vmware.com/security/advisories/VMSA-2015-0007.html | 2018-08-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Vcenter Server Search vendor "Vmware" for product "Vcenter Server" | 5.0 Search vendor "Vmware" for product "Vcenter Server" and version "5.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vcenter Server Search vendor "Vmware" for product "Vcenter Server" | 5.1 Search vendor "Vmware" for product "Vcenter Server" and version "5.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vcenter Server Search vendor "Vmware" for product "Vcenter Server" | 5.5 Search vendor "Vmware" for product "Vcenter Server" and version "5.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vcenter Server Search vendor "Vmware" for product "Vcenter Server" | 6.0 Search vendor "Vmware" for product "Vcenter Server" and version "6.0" | - |
Affected
|