PT-2015-7412 · Vmware+1 · Vcenter Orchestrator+5

Published

2015-12-21

·

Updated

2016-11-28

·

CVE-2015-6934

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VMware vRealize Orchestrator versions 6.x vCenter Orchestrator versions 5.x vRealize Operations versions 6.x vCenter Operations versions 5.x vCenter Application Discovery Manager (vADM) versions 7.x
Description The issue allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. This is due to a problem with serialized-object interfaces in the affected products.
Recommendations For VMware vRealize Orchestrator versions 6.x, update to a version that includes a fix for the Apache Commons Collections library issue. For vCenter Orchestrator versions 5.x, update to a version that includes a fix for the Apache Commons Collections library issue. For vRealize Operations versions 6.x, update to a version that includes a fix for the Apache Commons Collections library issue. For vCenter Operations versions 5.x, update to a version that includes a fix for the Apache Commons Collections library issue. For vCenter Application Discovery Manager (vADM) versions 7.x, update to a version that includes a fix for the Apache Commons Collections library issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6934

Affected Products

Apache Commons Collections
Vmware Vrealize Orchestrator
Vcenter Application Discovery Manager
Vcenter Operations
Vcenter Orchestrator
Vrealize Operations