CVE-2015-2342

critical
Published 2015-10-12 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.vmware.com/security/advisories/VMSA-2015-0007.html

Application impact

VendorProductVersionsFixed
vmwarevcenter_server5.0
vmwarevcenter_server5.1
vmwarevcenter_server5.5
vmwarevcenter_server6.0

References

Verify integrity in audit chain (admin only). AS-IS.