CVE-2015-7501
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x;…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 85.56% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- redhat/data grid · redhat/jboss a-mq · redhat/jboss bpm suite · redhat/jboss data virtualization · redhat/jboss enterprise application platform · redhat/jboss enterprise brms platform · redhat/jboss enterprise soa platform · redhat/jboss enterprise web server · redhat/jboss fuse · redhat/jboss fuse service works · redhat/jboss operations network · redhat/jboss portal · redhat/openshift · redhat/subscription asset manager · redhat/xpaas
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-2500.html
- http://rhn.redhat.com/errata/RHSA-2015-2501.html
- http://rhn.redhat.com/errata/RHSA-2015-2502.html
- http://rhn.redhat.com/errata/RHSA-2015-2514.html
- http://rhn.redhat.com/errata/RHSA-2015-2516.html
- http://rhn.redhat.com/errata/RHSA-2015-2517.html
- http://rhn.redhat.com/errata/RHSA-2015-2521.html
- http://rhn.redhat.com/errata/RHSA-2015-2522.html
- http://rhn.redhat.com/errata/RHSA-2015-2524.html
- http://rhn.redhat.com/errata/RHSA-2015-2670.html
- http://rhn.redhat.com/errata/RHSA-2015-2671.html
- http://rhn.redhat.com/errata/RHSA-2016-0040.html
- http://rhn.redhat.com/errata/RHSA-2016-1773.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/78215Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034097Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037052Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037053Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037640Third Party Advisory, VDB Entry
- https://access.redhat.com/security/vulnerabilities/2059393Vendor Advisory
- https://access.redhat.com/solutions/2045023Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1279330Issue Tracking, Third Party Advisory, VDB Entry, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2015-2536.html
- https://security.netapp.com/advisory/ntap-20240216-0010/
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://rhn.redhat.com/errata/RHSA-2015-2500.html
- http://rhn.redhat.com/errata/RHSA-2015-2501.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.