CVE-2015-7450

CVE Published 2016-01-02
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) ibm
Related Product(s) watson_explorer_analytical_components, watson_explorer_annotation_administration_console, sterling_b2b_integrator, websphere_application_server, watson_content_analytics, tivoli_common_reporting, sterling_integrator
Exploitation Reported (CISA KEV) 2022-01-10
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References