VMware vCenter Server jmx rmi remote code execution vulnerability in CVE-2015-2342)
VMware vCenter Server jmx rmi remote code execution vulnerability in CVE-2015-2342)
Release date:
Updated on:
Affected Systems:
VMWare vCenter Server
Description:
CVE (CAN) ID: CVE-2015-2342
VMware vCenter Server allows you to quickly deploy virtual machines and monitor the performance of physical servers and virtual machines. You can deploy, monitor, and manage virtualized IT environments on a single interface and ensure the best service level.
A security vulnerability exists in JMX remote interface configuration of VMware vCenter Server. Remote attackers can use this interface to register controlled mbeans and execute remote code in the system context.
<* Source: anonymous
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-455/
*>
Suggestion:
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.vmware.com/security/advisories/VMSA-2015-0007
This article permanently updates the link address: