CVE-2015-2683: Citrix Command Center

High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.

Affected products

  • Citrix Command Center: version 5.1 only; version 5.2 only

Published 2015-03-26. Last modified 2026-06-17.