PT-2015-7412 · Vmware+1 · Vcenter Orchestrator+5
Published
2015-12-21
·
Updated
2016-11-28
·
CVE-2015-6934
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VMware vRealize Orchestrator versions 6.x
vCenter Orchestrator versions 5.x
vRealize Operations versions 6.x
vCenter Operations versions 5.x
vCenter Application Discovery Manager (vADM) versions 7.x
Description
The issue allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. This is due to a problem with serialized-object interfaces in the affected products.
Recommendations
For VMware vRealize Orchestrator versions 6.x, update to a version that includes a fix for the Apache Commons Collections library issue.
For vCenter Orchestrator versions 5.x, update to a version that includes a fix for the Apache Commons Collections library issue.
For vRealize Operations versions 6.x, update to a version that includes a fix for the Apache Commons Collections library issue.
For vCenter Operations versions 5.x, update to a version that includes a fix for the Apache Commons Collections library issue.
For vCenter Application Discovery Manager (vADM) versions 7.x, update to a version that includes a fix for the Apache Commons Collections library issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Commons Collections
Vmware Vrealize Orchestrator
Vcenter Application Discovery Manager
Vcenter Operations
Vcenter Orchestrator
Vrealize Operations