CVE-2015-7501
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
- Affected products
- Apache Commons Collections, Centos, Debian, Red Hat, Red Hat Bpm Suite, Red Hat Brms, Red Hat Datagrid, Red Hat Data Virtualization
- Redhat Data Grid
- = 6.0.0
- Redhat Jboss A-mq
- = 6.0.0
- Redhat Jboss Bpm Suite
- = 6.0.0
- Redhat Jboss Data Virtualization
- = 5.0.0, 6.0.0
- Redhat Jboss Enterprise Application Platform
- = 4.3.0, 5.0.0, 6.0.0
- Redhat Jboss Enterprise Brms Platform
- = 5.0.0, 6.0.0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 85.6% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2017-11-09
CVE-2015-7501 at NVD
9 known exploits for CVE-2015-7501
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2015-7501
osv-java-poc
Exploit for Deserialization of Untrusted Data in Ibm Sterling_B2B_Integrator
Exploit for Deserialization of Untrusted Data in Redhat Data_Grid
Exploit for Deserialization of Untrusted Data in Redhat Data_Grid
Exploit for Deserialization of Untrusted Data in Redhat Data_Grid
Immunity Canvas: JBOSS6_JMXINVOKERSERVLET_DESERIALIZE
Immunity Canvas: WEBLOGIC_T3_DESERIALIZATION
Red Hat JBoss Portal安全绕过漏洞