CVE-2015-7450
Last modified
CVE-2015-7450 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.. CISA has confirmed active exploitation in the wild. EPSS estimates a 97.66% chance of exploitation in the next 30 days.
Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling B2b Integrator | 5.2 |
| Ibm | Sterling Integrator | 5.1 |
| Ibm | Tivoli Common Reporting | 2.1 |
| Ibm | Tivoli Common Reporting | 2.1.1 |
| Ibm | Tivoli Common Reporting | 2.1.1.2 |
| Ibm | Tivoli Common Reporting | 3.1 |
| Ibm | Tivoli Common Reporting | 3.1.0.1 |
| Ibm | Tivoli Common Reporting | 3.1.0.2 |
| Ibm | Tivoli Common Reporting | 3.1.2 |
| Ibm | Tivoli Common Reporting | 3.1.2.1 |
| Ibm | Watson Content Analytics | >= 3.0, <= 3.0.0.6 |
| Ibm | Watson Content Analytics | >= 3.5, <= 3.5.0.3 |
| Ibm | Watson Explorer Analytical Components | >= 10.0, <= 10.0.0.2 |
| Ibm | Watson Explorer Analytical Components | 11.0 |
| Ibm | Watson Explorer Annotation Administration Console | >= 10.0, <= 10.0.0.2 |
| Ibm | Watson Explorer Annotation Administration Console | 11.0 |
| Ibm | Websphere Application Server | 7.0.0.0 |
| Ibm | Websphere Application Server | 8.0.0.0 |
| Ibm | Websphere Application Server | 8.5 |
| Ibm | Websphere Application Server | 8.5.0.0 |
| Ibm | Websphere Application Server | 8.5.5.5 |
References
- https://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
- https://www.securityfocus.com/bid/77653Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1035125Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41613/Exploit, Third Party Advisory, VDB Entry
- https://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
- https://www.securityfocus.com/bid/77653Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1035125Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41613/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7450US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2015-7450?
How severe is CVE-2015-7450?
How do I fix CVE-2015-7450?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7444The Update Installer in IBM WebSphere Commerce Enterprise 7.…
- CVE-2015-7445IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1…
- CVE-2015-7446Cross-site request forgery (CSRF) vulnerability in IBM Flash…
- CVE-2015-7447IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 throu…
- CVE-2015-7448SQL injection vulnerability in IBM Maximo Asset Management 7…
- CVE-2015-7449IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x …
- CVE-2015-7451Cross-site scripting (XSS) vulnerability in IBM Maximo Asset…
- CVE-2015-7452IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 b…
- CVE-2015-7453Cross-site scripting (XSS) vulnerability in IBM Rational Col…
- CVE-2015-7454Business Space in IBM WebSphere Process Server 6.1.2.0 throu…
- CVE-2015-7455IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before …
- CVE-2015-7456IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows…
Are you affected by CVE-2015-7450?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
