VDB
RHSA-2015:1947
RHSA-2015:1947
PUBLISHED
CVSS 7.5 HIGH
It was found that Apache Cassandra bound an unauthenticated JMX/RMI interface to all network interfaces. A remote attacker able to access the RMI, an API for the transport and remote execution of serialized Java, could use this flaw to execute arbitrary code as the user running Cassandra.
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Operations Network 3.3 |
Timeline
- Oct 28, 2015 CVE Published
- Nov 21, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2015:1947 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=em&downloadType=securityPatches&version=3.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1035481 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1208181 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1212407 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1230411 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1232847 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1234651 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1234912 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1243545 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1244941 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1247311 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1251503 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1252136 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1252142 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1252458 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1255821 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1256329 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1258870 issue
…and 6 more