CVE-2015-7450

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.487

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-7450 are fixed in IBM HTTP 17.0.0.4Windows
Vulnerabilities CVE-2015-7450 are fixed in IBM HTTP 8.5.5.8Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.12Windows
Vulnerabilities CVE-2015-7450 are fixed in IBM HTTP 7.0.0.41Windows
Vulnerabilities CVE-2019-10086,CVE-2015-7450 are fixed in IBM WebSphere 9.0.5.2Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.12Windows
Vulnerabilities CVE-2015-7450 are fixed in IBM WebSphere 17.0.0.4Windows
Vulnerabilities CVE-2015-7450 are fixed in IBM WebSphere 8.5.5.8Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.41Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.5Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.6Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.7Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.8Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234