S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2015-3337 Scanner

CVE-2015-3337 scanner - Directory Traversal vulnerability in Elasticsearch

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
4
Times Used
by S4E users
2
Assets Scanned
domains & IPs
4
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-3337
4.3
CVSS

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

Elasticsearch is a search engine based on the Lucene library. It is commonly used by companies to store, search, analyze, and visualize large amounts of data in real-time. Elasticsearch is an open-source solution, and it is particularly useful for those who require fast searching capabilities.

CVE-2015-3337 is a directory traversal vulnerability that was detected in Elasticsearch before version 1.4.5 and 1.5.x before 1.5.2. The vulnerability allows remote attackers to read arbitrary files via unspecified vectors when a site plugin is enabled. Once an attacker has access to the filesystem, they can modify, delete, or steal confidential information. This vulnerability is a serious security threat that should be addressed immediately.

Exploiting the vulnerability can lead to a number of disastrous consequences for organizations. A malicious actor can gain unauthorized access to sensitive data, such as user credentials, payment information, and private documents. This information can then be used for financial gain or in more complex cyber attacks, such as phishing, social engineering, and ransomware. The end result can be devastating for businesses, causing reputational damage, legal implications, and financial losses.

At s4e.io, we provide pro features that allow individuals and organizations to easily and quickly learn about vulnerabilities in their digital assets. With our platform, users can run automated vulnerability scans, receive alerts for new vulnerabilities, and get actionable recommendations on how to address them. Our threat intelligence is continuously updated and is sourced from the world's leading security researchers and organizations. This means that our users can stay ahead of the latest security threats and protect their digital assets effectively.

 

REFERENCES

Solution Advice

Organizations can follow certain precautions to mitigate the risk of this vulnerability. These are:

  • Upgrade to the latest version of Elasticsearch as soon as possible.
  • Disable any unsafe plugins that are not required.
  • Limit access to Elasticsearch by enforcing strong password policies and access control measures.
  • Ensure that data backups are current and properly stored offsite.
  • Monitor Elasticsearch logs for any signs of unauthorized activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-3337 scanner - Directory Traversal vulnerability in Elasticsearch S4E