peter bassill · operator
$ cve CVE-2015-7450 JSON

CVE-2015-7450 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 97.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-10.

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.76% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-07-10
Public exploityes
Published2016-01-02
Last modified2026-06-17

CISA KEV

NameIBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Added2022-01-10
Due2022-07-10
Vendor / productIBM / WebSphere Application Server and Server Hypervisor Edition
Ransomware usenone reported

Affected (7)

VendorProduct
ibmsterling b2b integrator
ibmsterling integrator
ibmtivoli common reporting
ibmwatson content analytics
ibmwatson explorer analytical components
ibmwatson explorer annotation administration console
ibmwebsphere application server

Public exploits

SourceTitleDate
exploit-dbIBM WebSphere - RCE Java Deserialization (Metasploit)2017-03-15

References

→ the Explorer  ·  watch your stack  ·  NVD