CVE-2015-2002: Critical severity esri arcgis runtime sdk vulnerability
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2002?
CVE-2015-2002 is rated as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2015-2002?
To fix CVE-2015-2002, update to a version of the ESRI ArcGis Runtime SDK for Android later than 10.2.6-2.
What software is affected by CVE-2015-2002?
CVE-2015-2002 affects the ESRI ArcGis Runtime SDK for Android before version 10.2.6-2.
What type of attack can exploit CVE-2015-2002?
CVE-2015-2002 can be exploited by attackers to execute arbitrary code through an improperly handled pointer in a Serializable class.
Is CVE-2015-2002 a persistent vulnerability?
CVE-2015-2002 is not a persistent vulnerability as it affects specific SDK versions prior to 10.2.6-2.