← All CVEs

CVE-2015-3292

high · 10

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

10
CVSS
12.2%
EPSS (exploit prob.)
96th
EPSS percentile
2015-05-31
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-17

Affected products

VendorProductAffected versions
netapponcommand_workflow_automation<= 2.2.1
netapponcommand_workflow_automation3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-3292