CVE-2015-1499: High severity samsung security manager vulnerability
Published Feb 16, 2015
·Updated
The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial of service, via a DELETE request.
Affected Software
1 affected component
Samsung Samsung Security Manager<=1.30
Event History
Feb 16, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1499?
CVE-2015-1499 is considered a high severity vulnerability that allows remote attackers to delete arbitrary files.
2
How do I fix CVE-2015-1499?
To fix CVE-2015-1499, upgrade to Samsung Security Manager version 1.31 or later.
3
What type of attack is enabled by CVE-2015-1499?
CVE-2015-1499 enables remote attackers to perform a denial of service attack through file deletion.
4
Which versions of Samsung Security Manager are affected by CVE-2015-1499?
Samsung Security Manager versions prior to 1.31 are affected by CVE-2015-1499.
5
Can CVE-2015-1499 be exploited without authentication?
Yes, CVE-2015-1499 can be exploited without authentication via a specially crafted DELETE request.