CVE-2015-7450: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7450?
CVE-2015-7450 has a moderate severity rating, allowing remote command execution via crafted serialized Java objects.
How do I fix CVE-2015-7450?
To fix CVE-2015-7450, update your affected IBM products to the latest versions that are not vulnerable.
Which IBM products are affected by CVE-2015-7450?
CVE-2015-7450 impacts several IBM products including IBM Tivoli Common Reporting and IBM WebSphere Application Server.
Can CVE-2015-7450 be exploited remotely?
Yes, CVE-2015-7450 can be exploited remotely by attackers leveraging crafted serialized Java objects.
What type of vulnerability is CVE-2015-7450?
CVE-2015-7450 is classified as a deserialization vulnerability that enables remote command execution.