{"api_version":"1","generated_at":"2026-07-23T07:49:06+00:00","cve":"CVE-2015-2342","urls":{"html":"https://cve.report/CVE-2015-2342","api":"https://cve.report/api/cve/CVE-2015-2342.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-2342","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-2342"},"summary":{"title":"CVE-2015-2342","description":"The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-10-12 10:59:01","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html","name":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"VMSA-2015-0007.2 | United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033720","name":"http://www.securitytracker.com/id/1033720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware vCenter Bugs Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2015/Oct/1","name":"http://seclists.org/fulldisclosure/2015/Oct/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Full Disclosure: CVE-2015-2342 VMware vCenter Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76930","name":"http://www.securityfocus.com/bid/76930","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware vCenter Server CVE-2015-2342 Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/","name":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CVE-2015-2342 VMware vCenter Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-455","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-455","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-2342","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2342","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"2342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"2342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:10:16.151Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20151001 CVE-2015-2342 VMware vCenter Remote Code Execution","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2015/Oct/1"},{"name":"1033720","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033720"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-455"},{"name":"76930","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76930"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-10-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-08-11T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20151001 CVE-2015-2342 VMware vCenter Remote Code Execution","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2015/Oct/1"},{"name":"1033720","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033720"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-455"},{"name":"76930","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76930"},{"tags":["x_refsource_MISC"],"url":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-2342","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20151001 CVE-2015-2342 VMware vCenter Remote Code Execution","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2015/Oct/1"},{"name":"1033720","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033720"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-455","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-455"},{"name":"76930","refsource":"BID","url":"http://www.securityfocus.com/bid/76930"},{"name":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/","refsource":"MISC","url":"https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/"},{"name":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2015-0007.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-2342","datePublished":"2015-10-12T10:00:00.000Z","dateReserved":"2015-03-18T00:00:00.000Z","dateUpdated":"2024-08-06T05:10:16.151Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-10-12 10:59:01","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"46C704E0-E165-4A44-A104-6C5B83A83237"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:5.1:*:*:*:*:*:*:*","matchCriteriaId":"E0492A2B-EBE2-4303-B8BD-8511D191D1AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:5.5:*:*:*:*:*:*:*","matchCriteriaId":"8B12523A-5C1E-408F-BB4B-98EF32C7D676"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"7499E57A-1F9C-45F0-93F8-F3FB7B0F990F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"2342","Ordinal":"1","Title":"CVE-2015-2342","CVE":"CVE-2015-2342","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"2342","Ordinal":"1","NoteData":"The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.","Type":"Description","Title":"CVE-2015-2342"},{"CveYear":"2015","CveId":"2342","Ordinal":"2","NoteData":"2015-10-12","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"2342","Ordinal":"3","NoteData":"2018-08-11","Type":"Other","Title":"Modified"}]}}}