{"id":"CVE-2015-0225","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-0225","summary":"Improper Neutralization of Special Elements used in a Command  in Apache Cassandra","details":"The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.","published":"2022-05-14T02:49:56Z","modified":"2024-12-05T05:43:23.250314Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.cassandra:apache-cassandra","fixedVersion":"2.0.14"},{"ecosystem":"Maven","name":"org.apache.cassandra:apache-cassandra","fixedVersion":"2.1.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0225"},{"type":"WEB","url":"http://packetstormsecurity.com/files/131249/Apache-Cassandra-Remote-Code-Execution.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1947.html"},{"type":"WEB","url":"http://www.mail-archive.com/user@cassandra.apache.org/msg41819.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:43:23.250314Z"}}