peter bassill · operator
$ cve CVE-2015-2342 JSON

CVE-2015-2342 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 89% (pctl 100)

Patch early

A public exploit exists.

Description

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS89.05% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2015-10-12
Last modified2026-06-17

Affected (1)

VendorProduct
vmwarevcenter server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD