7.5
CVSSv2

CVE-2015-0225

Published: 03/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default configuration in Apache Cassandra 1.2.0 up to and including 1.2.19, 2.0.0 up to and including 2.0.13, and 2.1.0 up to and including 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote malicious users to execute arbitrary Java code via an RMI request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache cassandra 1.2.12

apache cassandra 1.2.6

apache cassandra 1.2.2

apache cassandra 1.2.3

apache cassandra 2.1.2

apache cassandra 2.0.13

apache cassandra 1.2.5

apache cassandra 1.2.13

apache cassandra 2.0.2

apache cassandra 2.0.4

apache cassandra 2.1.1

apache cassandra 2.0.8

apache cassandra 1.2.9

apache cassandra 2.0.7

apache cassandra 2.0.1

apache cassandra 1.2.1

apache cassandra 2.0.11

apache cassandra 1.2.11

apache cassandra 2.0.3

apache cassandra 1.2.14

apache cassandra 1.2.15

apache cassandra 1.2.8

apache cassandra 2.0.10

apache cassandra 2.0.9

apache cassandra 1.2.4

apache cassandra 1.2.17

apache cassandra 2.0.12

apache cassandra 1.2.10

apache cassandra 2.1.3

apache cassandra 2.1.0

apache cassandra 1.2.0

apache cassandra 1.2.19

apache cassandra 2.0.5

apache cassandra 1.2.16

apache cassandra 1.2.7

apache cassandra 2.0.0

apache cassandra 1.2.18

apache cassandra 2.0.6

Vendor Advisories

It was found that Apache Cassandra bound an unauthenticated JMX/RMI interface to all network interfaces A remote attacker able to access the RMI, an API for the transport and remote execution of serialized Java, could use this flaw to execute arbitrary code as the user running Cassandra ...

Github Repositories

[DEPRECATED] This project is deprecated. It will be archived on December 1, 2017.

DEPRECATED This project has been replaced by DC/OS Cassandra Service githubcom/mesosphere/mesosphere/dcos-commons/frameworks/cassandra Cassandra Mesos Framework ------------ DISCLAIMER This is a very early version of Cassandra-Mesos framework This document, code behavior, and anything else may change without notice and/or break older installations Documentation