First published: Sat Jan 02 2016(Updated: )
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Common Reporting | =2.1 | |
IBM Tivoli Common Reporting | =2.1.1 | |
IBM Tivoli Common Reporting | =2.1.1.2 | |
IBM Tivoli Common Reporting | =3.1 | |
IBM Tivoli Common Reporting | =3.1.0.1 | |
IBM Tivoli Common Reporting | =3.1.0.2 | |
IBM Tivoli Common Reporting | =3.1.2 | |
IBM Tivoli Common Reporting | =3.1.2.1 | |
IBM Sterling B2B Integrator | =5.2 | |
IBM Sterling Integrator | =5.1 | |
Ibm Watson Content Analytics | >=3.0<=3.0.0.6 | |
Ibm Watson Content Analytics | >=3.5<=3.5.0.3 | |
Ibm Watson Explorer Analytical Components | >=10.0<=10.0.0.2 | |
Ibm Watson Explorer Analytical Components | =11.0 | |
Ibm Watson Explorer Annotation Administration Console | >=10.0<=10.0.0.2 | |
Ibm Watson Explorer Annotation Administration Console | =11.0 | |
Ibm Websphere Application Server | =7.0.0.0 | |
Ibm Websphere Application Server | =8.0.0.0 | |
Ibm Websphere Application Server | =8.5 | |
Ibm Websphere Application Server | =8.5.0.0 | |
Ibm Websphere Application Server | =8.5.5.5 | |
IBM WebSphere Application Server and Server Hypervisor Edition | ||
=5.2 | ||
=5.1 | ||
=2.1 | ||
=2.1.1 | ||
=2.1.1.2 | ||
=3.1 | ||
=3.1.0.1 | ||
=3.1.0.2 | ||
=3.1.2 | ||
=3.1.2.1 | ||
>=3.0<=3.0.0.6 | ||
>=3.5<=3.5.0.3 | ||
>=10.0<=10.0.0.2 | ||
=11.0 | ||
>=10.0<=10.0.0.2 | ||
=11.0 | ||
=7.0.0.0 | ||
=8.0.0.0 | ||
=8.5 | ||
=8.5.0.0 | ||
=8.5.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.