SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-7501

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x;…

CRITICAL 9.8EPSS 85.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 85.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
85.56% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
redhat/data grid · redhat/jboss a-mq · redhat/jboss bpm suite · redhat/jboss data virtualization · redhat/jboss enterprise application platform · redhat/jboss enterprise brms platform · redhat/jboss enterprise soa platform · redhat/jboss enterprise web server · redhat/jboss fuse · redhat/jboss fuse service works · redhat/jboss operations network · redhat/jboss portal · redhat/openshift · redhat/subscription asset manager · redhat/xpaas
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.