10

CVE-2015-7501

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatData Grid Version6.0.0
RedhatJboss A-mq Version6.0.0
RedhatJboss Bpm Suite Version6.0.0
RedhatJboss Fuse Version6.0.0
RedhatJboss Portal Version6.0.0
RedhatOpenshift Version3.0 SwEditionenterprise
RedhatXpaas Version3.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 71.46% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securitytracker.com/id/1037053
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037640
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037052
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/78215
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034097
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1279330
Third Party Advisory
Vendor Advisory
VDB Entry
Issue Tracking