10

CVE-2015-7450

Warnung
Exploit
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling B2b Integrator Version 5.2
Ibm ≫ Sterling Integrator Version 5.1
Ibm ≫ Tivoli Common Reporting Version 2.1
Ibm ≫ Tivoli Common Reporting Version 2.1.1
Ibm ≫ Tivoli Common Reporting Version 2.1.1.2
Ibm ≫ Tivoli Common Reporting Version 3.1
Ibm ≫ Tivoli Common Reporting Version 3.1.0.1
Ibm ≫ Tivoli Common Reporting Version 3.1.0.2
Ibm ≫ Tivoli Common Reporting Version 3.1.2
Ibm ≫ Tivoli Common Reporting Version 3.1.2.1
Ibm ≫ Watson Content Analytics Version >= 3.0 <= 3.0.0.6
Ibm ≫ Watson Content Analytics Version >= 3.5 <= 3.5.0.3
Ibm ≫ Watson Explorer Analytical Components Version >= 10.0 <= 10.0.0.2
Ibm ≫ Websphere Application Server Version 7.0.0.0 SwEdition -
Ibm ≫ Websphere Application Server Version 8.0.0.0 SwEdition -
Ibm ≫ Websphere Application Server Version 8.5 SwEdition traditional
Ibm ≫ Websphere Application Server Version 8.5.0.0 SwEdition hypervisor
Ibm ≫ Websphere Application Server Version 8.5.5.5 SwEdition liberty

10.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Schwachstelle

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.66% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www-01.ibm.com/support/docview.wss?uid=swg21972799
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21970575
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21971342
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21971376
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21971733
Broken Link
http://www-01.ibm.com/support/docview.wss?uid=swg21971758
Vendor Advisory
http://www.securityfocus.com/bid/77653
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1035125
Third Party Advisory
Broken Link
VDB Entry
https://www.exploit-db.com/exploits/41613/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7450
US Government Resource