CVE-2015-2683

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:citrix:command_center:5.1:*:*:*:*:*:*:*
cpe:2.3:a:citrix:command_center:5.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:27

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/130930/Citrx-Command-Center-Advent-JMX-Servlet-Accessible.html - Exploit () http://packetstormsecurity.com/files/130930/Citrx-Command-Center-Advent-JMX-Servlet-Accessible.html - Exploit
References () http://seclists.org/fulldisclosure/2015/Mar/127 - () http://seclists.org/fulldisclosure/2015/Mar/127 -
References () http://support.citrix.com/article/CTX200584 - () http://support.citrix.com/article/CTX200584 -
References () http://www.securityfocus.com/archive/1/534933/100/0/threaded - () http://www.securityfocus.com/archive/1/534933/100/0/threaded -
References () http://www.securityfocus.com/bid/73313 - () http://www.securityfocus.com/bid/73313 -
References () http://www.securitytracker.com/id/1031993 - () http://www.securitytracker.com/id/1031993 -
References () https://www.securify.nl/advisory/SFY20140804/advent_jmx_servlet_of_citrx_command_center_is_accessible_to_unauthenticated_users.html - Exploit () https://www.securify.nl/advisory/SFY20140804/advent_jmx_servlet_of_citrx_command_center_is_accessible_to_unauthenticated_users.html - Exploit

Information

Published : 2015-03-26 14:59

Updated : 2024-11-21 02:27


NVD link : CVE-2015-2683

Mitre link : CVE-2015-2683

CVE.ORG link : CVE-2015-2683


JSON object : View

Products Affected

citrix

  • command_center
CWE
CWE-264

Permissions, Privileges, and Access Controls