CVE-2015-3292

critical
Published 2015-05-31 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://kb.netapp.com/support/index?page=content&id=9010037

Application impact

VendorProductVersionsFixed
netapponcommand_workflow_automation{"endIncluding":"2.2.1"}
netapponcommand_workflow_automation3.0

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.