Vulnerability CVE-2015-3292


Published: 2015-05-31

Description:
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Netapp -> Oncommand workflow automation 

 References:
http://www.securityfocus.com/bid/74891
https://kb.netapp.com/support/index?page=content&id=9010037

Copyright 2024, cxsecurity.com

 

Back to Top