CVE-2015-7450
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 97.66% probability · 100th percentile
- CISA KEV
- Listed 10 January 2022 · due 10 July 2022
- Weakness
- CWE-502
- Affected
- ibm/sterling b2b integrator · ibm/sterling integrator · ibm/tivoli common reporting · ibm/watson content analytics · ibm/watson explorer analytical components · ibm/watson explorer annotation administration console · ibm/websphere application server
- Source
- psirt@us.ibm.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2015-7450
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971733Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
- http://www.securityfocus.com/bid/77653Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035125Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41613/Exploit, Third Party Advisory, VDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971733Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
- http://www.securityfocus.com/bid/77653Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035125Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41613/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7450US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.