CVE-2015-7450

Confirmed PUBLISHED

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow...

Vendor: IBM Product: WebSphere
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 97.7%

At a Glance

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

apache java nuclei_scanner metasploit cisa
CVE Published
Jan 02, 2016
Exploitation Reported
Jan 10, 2022
CVSS
9.8 Critical
EPSS
97.7%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 41613 exploit-db.com · Exploit https://www.exploit-db.com/exploits/41613/
  • 77653 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/77653
  • 1035125 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1035125
  • www-01.ibm.com/support/docview.wss www-01.ibm.com · CVE Record http://www-01.ibm.com/support/docview.wss?uid=swg21971733
  • www-01.ibm.com/support/docview.wss www-01.ibm.com · CVE Record http://www-01.ibm.com/support/docview.wss?uid=swg21971342
Show 4 more references