← Vulnerability feed

Vulnerability record · CVE-2015-3188 · published 13 January 2017

CVE-2015-3188: Apache storm permissions and access controls vulnerability

Apache · Storm

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

9.8 CVSS 3.0 Critical EPSS 14% · top 3.5% CWE-264 · Permissions and access controls
9.8CVSS 3.0 base score, v2 10.0
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3188 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40865Apache Storm supervisor worker unsafe deserialization RCEApache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rat…EPSS 66%analysed9.8CVE-2021-38294Apache Storm Nimbus getTopologyHistory pre-auth command injectionApache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm…EPSS 84%analysed9.8CVE-2018-11779Apache storm deserialization of untrusted data vulnerabilityIn Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…EPSS 3.5%8.8CVE-2026-35337Apache storm deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials s…EPSS 1.1%8.8CVE-2018-1331Apache storm vulnerabilityIn Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm c…EPSS 4.4%8.8CVE-2017-9799Apache storm vulnerabilityIt was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for …EPSS 4.9%7.5CVE-2019-0202Apache storm information exposure vulnerabilityThe Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…EPSS 2.0%7.5CVE-2014-0115Apache storm path traversal vulnerabilityDirectory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2015-3188), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.