CVE-2015-2857: Command Injection
Published Aug 22, 2017
·Updated
Accellion File Transfer Appliance before FTA911210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauthtoken parameter.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_11_200
Event History
Aug 22, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2857?
CVE-2015-2857 is considered a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2015-2857?
To fix CVE-2015-2857, upgrade the Accellion File Transfer Appliance to version 9_11_210 or later.
3
What is affected by CVE-2015-2857?
CVE-2015-2857 affects Accellion File Transfer Appliance versions up to 9_11_200.
4
What types of attacks can exploit CVE-2015-2857?
CVE-2015-2857 can be exploited by remote attackers to execute arbitrary code through malicious oauth_token parameters.
5
When was CVE-2015-2857 disclosed?
CVE-2015-2857 was disclosed in July 2015.