Unrated severityNVD Advisory· Published Apr 8, 2015· Updated May 6, 2026
CVE-2015-2828
CVE-2015-2828
Description
CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.
Affected products
2cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*
- cpe:2.3:a:broadcom:spectrum:9.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150407-01-security-notice-for-ca-spectrum.aspxnvdVendor Advisory
- packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.htmlnvd
- www.securityfocus.com/archive/1/535205/100/0/threadednvd
- www.securityfocus.com/bid/73957nvd
News mentions
0No linked articles in our index yet.