First published: Sun May 31 2015(Updated: )
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp OnCommand Workflow Automation | <=2.2.1 | |
NetApp OnCommand Workflow Automation | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3292 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2015-3292, upgrade NetApp OnCommand Workflow Automation to version 2.2.1P1 or 3.0P1 or later.
CVE-2015-3292 affects NetApp OnCommand Workflow Automation versions below 2.2.1P1 and 3.0P1.
CVE-2015-3292 is a remote code execution vulnerability due to misconfigured Java Debugging Wire Protocol services.
Remote attackers can exploit CVE-2015-3292 to execute arbitrary code on vulnerable systems.