CVE-2015-2342 Information

Description

The JMX RMI service in VMware vCenter Server 5.0 before u3e 5.1 before u3b 5.5 before u3 and 6.0 before u1 does not restrict registration of MBeans which allows remote attackers to execute arbitrary code via the RMI protocol.

Reference

http://seclists.org/fulldisclosure/2015/Oct/1 http://www.securityfocus.com/bid/76930 http://www.securitytracker.com/id/1033720 http://www.vmware.com/security/advisories/VMSA-2015-0007.html http://www.zerodayinitiative.com/advisories/ZDI-15-455 https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/

Share on: