CVE-2015-3188: Apache Storm

Critical severity, CVSS 9.8. EPSS: 14.4% chance of exploitation in the next 30 days.

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Apache Storm: version 0.10.0 only

Published 2017-01-13. Last modified 2026-06-17.