VYPR
Unrated severityNVD Advisory· Published Apr 8, 2015· Updated May 6, 2026

CVE-2015-2828

CVE-2015-2828

Description

CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.

Affected products

2
  • cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:broadcom:spectrum:9.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.