peter bassill · operator
$ cve CVE-2015-7501 JSON

CVE-2015-7501

9.8
CRITICAL · CVSS 3.0 · EPSS 85.6% (pctl 100)

Patch early

EPSS 85.6% — above the 10% action threshold.

Description

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS85.56% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2017-11-09
Last modified2026-06-17

Affected (15)

VendorProduct
redhatdata grid
redhatjboss a-mq
redhatjboss bpm suite
redhatjboss data virtualization
redhatjboss enterprise application platform
redhatjboss enterprise brms platform
redhatjboss enterprise soa platform
redhatjboss enterprise web server
redhatjboss fuse
redhatjboss fuse service works
redhatjboss operations network
redhatjboss portal
redhatopenshift
redhatsubscription asset manager
redhatxpaas

References

→ the Explorer  ·  watch your stack  ·  NVD