Vulnerability Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling B2B Integrator | 5.2 |
| Ibm | Sterling Integrator | 5.1 |
| Ibm | Tivoli Common Reporting | 2.1 |
| Ibm | Watson Content Analytics | >= 3.0, <= 3.0.0.6 |
| Ibm | Watson Explorer Analytical Components | >= 10.0, <= 10.0.0.2 |
| Ibm | Watson Explorer Annotation Administration Console | >= 10.0, <= 10.0.0.2 |
| Ibm | Websphere Application Server | 7.0.0.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971733Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
- http://www.securityfocus.com/bid/77653Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035125Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41613/ExploitThird Party AdvisoryVDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg21970575Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971342Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971376Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21971733Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21971758Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21972799Vendor Advisory
FAQ
What is CVE-2015-7450?
CVE-2015-7450 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a craft...
How severe is CVE-2015-7450?
CVE-2015-7450 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-7450?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling B2B Integrator, Ibm Sterling Integrator, Ibm Tivoli Common Reporting, Ibm Watson Content Analytics, Ibm Watson Explorer Analytical Components.