CVE-2015-3292: Critical severity netapp oncommand workflow automation vulnerability
Published May 31, 2015
·Updated
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
2 affected components
NetApp OnCommand Workflow Automation<=2.2.1
NetApp OnCommand Workflow Automation=3.0
Event History
May 31, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3292?
CVE-2015-3292 has a medium severity rating due to its potential for remote code execution.
2
How do I fix CVE-2015-3292?
To fix CVE-2015-3292, upgrade NetApp OnCommand Workflow Automation to version 2.2.1P1 or 3.0P1 or later.
3
What systems are affected by CVE-2015-3292?
CVE-2015-3292 affects NetApp OnCommand Workflow Automation versions below 2.2.1P1 and 3.0P1.
4
What kind of vulnerability is CVE-2015-3292?
CVE-2015-3292 is a remote code execution vulnerability due to misconfigured Java Debugging Wire Protocol services.
5
Who can exploit CVE-2015-3292?
Remote attackers can exploit CVE-2015-3292 to execute arbitrary code on vulnerable systems.