Lucene search

K
cveRedhatCVE-2015-0225
HistoryApr 03, 2015 - 2:59 p.m.

CVE-2015-0225

2015-04-0314:59:00
CWE-77
redhat
web.nvd.nist.gov
62
apache cassandra
cve-2015-0225
remote attack
rmi
java code executable

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.7

Confidence

High

EPSS

0.008

Percentile

81.8%

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.

Affected configurations

Nvd
Node
apachecassandraMatch1.2.0
OR
apachecassandraMatch1.2.1
OR
apachecassandraMatch1.2.2
OR
apachecassandraMatch1.2.3
OR
apachecassandraMatch1.2.4
OR
apachecassandraMatch1.2.5
OR
apachecassandraMatch1.2.6
OR
apachecassandraMatch1.2.7
OR
apachecassandraMatch1.2.8
OR
apachecassandraMatch1.2.9
OR
apachecassandraMatch1.2.10
OR
apachecassandraMatch1.2.11
OR
apachecassandraMatch1.2.12
OR
apachecassandraMatch1.2.13
OR
apachecassandraMatch1.2.14
OR
apachecassandraMatch1.2.15
OR
apachecassandraMatch1.2.16
OR
apachecassandraMatch1.2.17
OR
apachecassandraMatch1.2.18
OR
apachecassandraMatch1.2.19
OR
apachecassandraMatch2.0.0
OR
apachecassandraMatch2.0.1
OR
apachecassandraMatch2.0.2
OR
apachecassandraMatch2.0.3
OR
apachecassandraMatch2.0.4
OR
apachecassandraMatch2.0.5
OR
apachecassandraMatch2.0.6
OR
apachecassandraMatch2.0.7
OR
apachecassandraMatch2.0.8
OR
apachecassandraMatch2.0.9
OR
apachecassandraMatch2.0.10
OR
apachecassandraMatch2.0.11
OR
apachecassandraMatch2.0.12
OR
apachecassandraMatch2.0.13
OR
apachecassandraMatch2.1.0
OR
apachecassandraMatch2.1.1
OR
apachecassandraMatch2.1.2
OR
apachecassandraMatch2.1.3
VendorProductVersionCPE
apachecassandra1.2.0cpe:2.3:a:apache:cassandra:1.2.0:*:*:*:*:*:*:*
apachecassandra1.2.1cpe:2.3:a:apache:cassandra:1.2.1:*:*:*:*:*:*:*
apachecassandra1.2.2cpe:2.3:a:apache:cassandra:1.2.2:*:*:*:*:*:*:*
apachecassandra1.2.3cpe:2.3:a:apache:cassandra:1.2.3:*:*:*:*:*:*:*
apachecassandra1.2.4cpe:2.3:a:apache:cassandra:1.2.4:*:*:*:*:*:*:*
apachecassandra1.2.5cpe:2.3:a:apache:cassandra:1.2.5:*:*:*:*:*:*:*
apachecassandra1.2.6cpe:2.3:a:apache:cassandra:1.2.6:*:*:*:*:*:*:*
apachecassandra1.2.7cpe:2.3:a:apache:cassandra:1.2.7:*:*:*:*:*:*:*
apachecassandra1.2.8cpe:2.3:a:apache:cassandra:1.2.8:*:*:*:*:*:*:*
apachecassandra1.2.9cpe:2.3:a:apache:cassandra:1.2.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 381

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.7

Confidence

High

EPSS

0.008

Percentile

81.8%