// For flags

CVE-2015-7450

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Interfaces de objetos serializados en determinados productos IBM analytics, business solutions, cognitive, IT infrastructure y mobile and social permiten a atacantes remotos ejecutar comandos arbitrarios a través de un objeto Java serializado manipulado, relacionado con la clase InvokerTransformer en la librería Apache Commons Collections.

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-09-29 CVE Reserved
  • 2015-11-06 First Exploit
  • 2016-01-02 CVE Published
  • 2022-01-10 Exploited in Wild
  • 2022-07-10 KEV Due Date
  • 2024-07-27 EPSS Updated
  • 2024-08-06 CVE Updated
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Sterling B2b Integrator
Search vendor "Ibm" for product "Sterling B2b Integrator"
5.2
Search vendor "Ibm" for product "Sterling B2b Integrator" and version "5.2"
-
Affected
Ibm
Search vendor "Ibm"
Sterling Integrator
Search vendor "Ibm" for product "Sterling Integrator"
5.1
Search vendor "Ibm" for product "Sterling Integrator" and version "5.1"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
2.1
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "2.1"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
2.1.1
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "2.1.1"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
2.1.1.2
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "2.1.1.2"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
3.1
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "3.1"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
3.1.0.1
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "3.1.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
3.1.0.2
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "3.1.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
3.1.2
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "3.1.2"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Common Reporting
Search vendor "Ibm" for product "Tivoli Common Reporting"
3.1.2.1
Search vendor "Ibm" for product "Tivoli Common Reporting" and version "3.1.2.1"
-
Affected
Ibm
Search vendor "Ibm"
Watson Content Analytics
Search vendor "Ibm" for product "Watson Content Analytics"
>= 3.0 <= 3.0.0.6
Search vendor "Ibm" for product "Watson Content Analytics" and version " >= 3.0 <= 3.0.0.6"
-
Affected
Ibm
Search vendor "Ibm"
Watson Content Analytics
Search vendor "Ibm" for product "Watson Content Analytics"
>= 3.5 <= 3.5.0.3
Search vendor "Ibm" for product "Watson Content Analytics" and version " >= 3.5 <= 3.5.0.3"
-
Affected
Ibm
Search vendor "Ibm"
Watson Explorer Analytical Components
Search vendor "Ibm" for product "Watson Explorer Analytical Components"
>= 10.0 <= 10.0.0.2
Search vendor "Ibm" for product "Watson Explorer Analytical Components" and version " >= 10.0 <= 10.0.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Watson Explorer Analytical Components
Search vendor "Ibm" for product "Watson Explorer Analytical Components"
11.0
Search vendor "Ibm" for product "Watson Explorer Analytical Components" and version "11.0"
-
Affected
Ibm
Search vendor "Ibm"
Watson Explorer Annotation Administration Console
Search vendor "Ibm" for product "Watson Explorer Annotation Administration Console"
>= 10.0 <= 10.0.0.2
Search vendor "Ibm" for product "Watson Explorer Annotation Administration Console" and version " >= 10.0 <= 10.0.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Watson Explorer Annotation Administration Console
Search vendor "Ibm" for product "Watson Explorer Annotation Administration Console"
11.0
Search vendor "Ibm" for product "Watson Explorer Annotation Administration Console" and version "11.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Application Server
Search vendor "Ibm" for product "Websphere Application Server"
7.0.0.0
Search vendor "Ibm" for product "Websphere Application Server" and version "7.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Application Server
Search vendor "Ibm" for product "Websphere Application Server"
8.0.0.0
Search vendor "Ibm" for product "Websphere Application Server" and version "8.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Application Server
Search vendor "Ibm" for product "Websphere Application Server"
8.5
Search vendor "Ibm" for product "Websphere Application Server" and version "8.5"
traditional
Affected
Ibm
Search vendor "Ibm"
Websphere Application Server
Search vendor "Ibm" for product "Websphere Application Server"
8.5.0.0
Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.0.0"
hypervisor
Affected
Ibm
Search vendor "Ibm"
Websphere Application Server
Search vendor "Ibm" for product "Websphere Application Server"
8.5.5.5
Search vendor "Ibm" for product "Websphere Application Server" and version "8.5.5.5"
liberty
Affected