CVE-2015-2683 Information

Description

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.

Reference

http://packetstormsecurity.com/files/130930/Citrx-Command-Center-Advent-JMX-Servlet-Accessible.html http://seclists.org/fulldisclosure/2015/Mar/127 http://support.citrix.com/article/CTX200584 http://www.securityfocus.com/archive/1/534933/100/0/threaded http://www.securityfocus.com/bid/73313 http://www.securitytracker.com/id/1031993 https://www.securify.nl/advisory/SFY20140804/advent_jmx_servlet_of_citrx_command_center_is_accessible_to_unauthenticated_users.html

Share on: