CVE-2015-3292

CRITICAL ⚠ Exploit

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary...

Affects 1 product across 1 vendor.

BCS8.93
CVSS 2.010.0
EPSS12.3%
Percentile96th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-17: CWE-17
◆ SAGE Intelligence — CITED Relevance Research Team

NetApp OnCommand Workflow Automation versions before 2.2.1P1 and 3.x before 3.0P1 are vulnerable to remote code execution due to the Java Debugging Wire Protocol (JDWP) service being enabled by default.

BSID: BS-2015-GLOBAL-160363-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-3292?
NetApp OnCommand Workflow Automation versions before 2.2.1P1 and 3.x before 3.0P1 are vulnerable to remote code execution due to the Java Debugging Wire Protocol (JDWP) service being enabled by default.
What is the CVSS score for CVE-2015-3292?
CVE-2015-3292 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 12.3%.
Is CVE-2015-3292 actively exploited?
Public exploit available for CVE-2015-3292. Exploitation risk elevated.
How do I remediate CVE-2015-3292?
Priority: IMMEDIATE. Advisory: https://kb.netapp.com/support/index?page=content&id=9010037 PSIRT: [email protected]
What systems are affected by CVE-2015-3292?
CVE-2015-3292 affects: Netapp.
Vulnerability Details
CVE IDCVE-2015-3292
BSIDBS-2015-GLOBAL-160363-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2015-05-31
Last Modified2026-05-06
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the JDWP service being exposed to the network, allowing attackers to connect and execute arbitrary code on the affected system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Netapp Oncommand Workflow Automation
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 4073 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Netapp
CVE-2014-9353 10.0 NetApp OnCommand Balance before 4.2P2 contains a "default privileged account,... CVE-2008-3349 10.0 Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp ... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2020-4561 10.0 IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control r... CVE-2021-21345 9.9 XStream is a Java library to serialize objects to XML and back again. In XStr...
View all Netapp CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →