CVE-2015-2828

CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:spectrum:9.3:*:*:*:*:*:*:*

History

21 Nov 2024, 02:28

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html - () http://packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html -
References () http://www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150407-01-security-notice-for-ca-spectrum.aspx - Vendor Advisory () http://www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150407-01-security-notice-for-ca-spectrum.aspx - Vendor Advisory
References () http://www.securityfocus.com/archive/1/535205/100/0/threaded - () http://www.securityfocus.com/archive/1/535205/100/0/threaded -
References () http://www.securityfocus.com/bid/73957 - () http://www.securityfocus.com/bid/73957 -

Information

Published : 2015-04-08 01:59

Updated : 2024-11-21 02:28


NVD link : CVE-2015-2828

Mitre link : CVE-2015-2828

CVE.ORG link : CVE-2015-2828


JSON object : View

Products Affected

broadcom

  • spectrum
CWE
CWE-264

Permissions, Privileges, and Access Controls