← All CVEs

CVE-2015-7450

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-01-10Remediation due 2022-07-10

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

9.8
CVSS
97.8%
EPSS (exploit prob.)
100th
EPSS percentile
2016-01-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
ibmsterling_b2b_integrator5.2
ibmsterling_integrator5.1
ibmtivoli_common_reporting2.1
ibmtivoli_common_reporting2.1.1
ibmtivoli_common_reporting2.1.1.2
ibmtivoli_common_reporting3.1
ibmtivoli_common_reporting3.1.0.1
ibmtivoli_common_reporting3.1.0.2
ibmtivoli_common_reporting3.1.2
ibmtivoli_common_reporting3.1.2.1
ibmwatson_content_analytics>= 3.0, <= 3.0.0.6
ibmwatson_content_analytics>= 3.5, <= 3.5.0.3
ibmwatson_explorer_analytical_components>= 10.0, <= 10.0.0.2
ibmwatson_explorer_analytical_components11.0
ibmwatson_explorer_annotation_administration_console>= 10.0, <= 10.0.0.2
ibmwatson_explorer_annotation_administration_console11.0
ibmwebsphere_application_server7.0.0.0
ibmwebsphere_application_server8.0.0.0
ibmwebsphere_application_server8.5
ibmwebsphere_application_server8.5.0.0
ibmwebsphere_application_server8.5.5.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-7450