CVE-2015-2683
Summary
| CVE | CVE-2015-2683 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-26 14:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Command Center | 5.1 | All | All | All |
| Application | Citrix | Command Center | 5.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Securify | af854a3a-2127-422b-91ae-364da2661108 | www.securify.nl | Exploit |
| Citrix Command Center 'Advent JMX' Servlet Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerabilities in Citrix Command Center Could Result in Credential Disclosure and Host Compromise | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | |
| Full Disclosure: Advent JMX Servlet of Citrx Command Center is accessible to unauthenticated users | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Citrix Command Center Bugs Let Remote Users Download Files and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Citrx Command Center Advent JMX Servlet Accessible ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.