First published: Fri Sep 28 2018(Updated: )
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC ESRS Policy Manager | <=6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15764 is a remote code execution vulnerability in Dell EMC ESRS Policy Manager versions 6.8 and prior.
CVE-2018-15764 has a severity rating of 9.8, which is classified as critical.
CVE-2018-15764 can be exploited by a remote unauthenticated attacker to execute arbitrary code in the server's JVM.
Dell EMC ESRS Policy Manager versions 6.8 and prior are affected by CVE-2018-15764.
At the time of writing, there is no official fix available for CVE-2018-15764. It is recommended to update to a newer version of Dell EMC ESRS Policy Manager when a fix is released.