CVE-2015-7450
CVE Published | 2016-01-02 |
---|---|
Related CWE(s) | CWE-94: Improper Control of Generation of Code ('Code Injection') |
Related Vendor(s) | ibm |
Related Product(s) | watson_explorer_analytical_components, watson_explorer_annotation_administration_console, sterling_b2b_integrator, websphere_application_server, watson_content_analytics, tivoli_common_reporting, sterling_integrator |
Exploitation Reported (CISA KEV) | 2022-01-10 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph