10

CVE-2015-7501

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatData Grid Version6.0.0
RedhatJboss A-mq Version6.0.0
RedhatJboss Bpm Suite Version6.0.0
RedhatJboss Fuse Version6.0.0
RedhatJboss Portal Version6.0.0
RedhatOpenshift Version3.0 SwEditionenterprise
RedhatXpaas Version3.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 71.46% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securitytracker.com/id/1037053
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037640
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037052
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/78215
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034097
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1279330
Third Party Advisory
Vendor Advisory
VDB Entry
Issue Tracking