CVE-2015-2683
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.
Citrix Command Center anterior a 5.1 Build 35.4 y 5.2 anterior a Build 42.7 no restringe correctamente el acceso al servlet Advent Java Management Extensions (JMX), lo que permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados en servlets/Jmx_dynamic.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-03-23 CVE Reserved
- 2015-03-26 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-11-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2015/Mar/127 | Mailing List | |
http://support.citrix.com/article/CTX200584 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/534933/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/73313 | Vdb Entry | |
http://www.securitytracker.com/id/1031993 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Command Center Search vendor "Citrix" for product "Command Center" | 5.1 Search vendor "Citrix" for product "Command Center" and version "5.1" | - |
Affected
| ||||||
Citrix Search vendor "Citrix" | Command Center Search vendor "Citrix" for product "Command Center" | 5.2 Search vendor "Citrix" for product "Command Center" and version "5.2" | - |
Affected
|