{"api_version":"1","generated_at":"2026-07-23T09:55:06+00:00","cve":"CVE-2015-7913","urls":{"html":"https://cve.report/CVE-2015-7913","api":"https://cve.report/api/cve/CVE-2015-7913.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7913","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7913"},"summary":{"title":"CVE-2015-7913","description":"ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.","state":"PUBLISHED","assigner":"icscert","published_at":"2015-11-21 11:59:25","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://zerodayinitiative.com/advisories/ZDI-15-572/","name":"http://zerodayinitiative.com/advisories/ZDI-15-572/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ZDI-15-572 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"Tibbo AggreGate Platform Vulnerabilities | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7913","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7913","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7913","vulnerable":"1","versionEndIncluding":"5.21.02","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibbo","cpe5":"aggregate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2015-7913","qid":"590557","title":"Tibbo AggreGate Platform Multiple Vulnerabilities (ICSA-15-323-01)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T08:06:30.978Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://zerodayinitiative.com/advisories/ZDI-15-572/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-11-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-11-21T03:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"http://zerodayinitiative.com/advisories/ZDI-15-572/"},{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2015-7913","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://zerodayinitiative.com/advisories/ZDI-15-572/","refsource":"MISC","url":"http://zerodayinitiative.com/advisories/ZDI-15-572/"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2015-7913","datePublished":"2015-11-21T11:00:00.000Z","dateReserved":"2015-10-22T00:00:00.000Z","dateUpdated":"2024-08-06T08:06:30.978Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-11-21 11:59:25","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tibbo:aggregate:*:*:*:*:*:*:*:*","versionEndIncluding":"5.21.02","matchCriteriaId":"CD2918B5-42D4-4E7A-B2E8-E35A0415F51B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7913","Ordinal":"1","Title":"CVE-2015-7913","CVE":"CVE-2015-7913","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7913","Ordinal":"1","NoteData":"ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.","Type":"Description","Title":"CVE-2015-7913"},{"CveYear":"2015","CveId":"7913","Ordinal":"2","NoteData":"2015-11-21","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7913","Ordinal":"3","NoteData":"2015-11-20","Type":"Other","Title":"Modified"}]}}}