CRITICAL · 9.8

CVE-2015-7501

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service ...

Vulnerability Description

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RedhatData Grid6.0.0
RedhatJboss A-Mq6.0.0
RedhatJboss Bpm Suite6.0.0
RedhatJboss Data Virtualization5.0.0
RedhatJboss Enterprise Application Platform4.3.0
RedhatJboss Enterprise Brms Platform5.0.0
RedhatJboss Enterprise Soa Platform5.0.0
RedhatJboss Enterprise Web Server3.0.0
RedhatJboss Fuse6.0.0
RedhatJboss Fuse Service Works6.0
RedhatJboss Operations Network3.0
RedhatJboss Portal6.0.0
RedhatOpenshift3.0
RedhatSubscription Asset Manager1.3.0
RedhatXpaas3.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7501?

CVE-2015-7501 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service ...

How severe is CVE-2015-7501?

CVE-2015-7501 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2015-7501?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Data Grid, Redhat Jboss A-Mq, Redhat Jboss Bpm Suite, Redhat Jboss Data Virtualization, Redhat Jboss Enterprise Application Platform.