CVE-2015-2342
Summary
| CVE | CVE-2015-2342 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-12 10:59:01 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Vcenter Server | 5.0 | All | All | All |
| Application | Vmware | Vcenter Server | 5.1 | All | All | All |
| Application | Vmware | Vcenter Server | 5.5 | All | All | All |
| Application | Vmware | Vcenter Server | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2015-0007.2 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| VMware vCenter Bugs Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Full Disclosure: CVE-2015-2342 VMware vCenter Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| VMware vCenter Server CVE-2015-2342 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2015-2342 VMware vCenter Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.7elements.co.uk | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.