CVE-2015-7450

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ibmCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
ibmsterling_b2b_integrator
5.2
ibmsterling_integrator
5.1
ibmtivoli_common_reporting
2.1
ibmtivoli_common_reporting
2.1.1
ibmtivoli_common_reporting
2.1.1.2
ibmtivoli_common_reporting
3.1
ibmtivoli_common_reporting
3.1.0.1
ibmtivoli_common_reporting
3.1.0.2
ibmtivoli_common_reporting
3.1.2
ibmtivoli_common_reporting
3.1.2.1
ibmwatson_content_analytics
3.0 ≤
𝑥
≤ 3.0.0.6
ibmwatson_content_analytics
3.5 ≤
𝑥
≤ 3.5.0.3
ibmwatson_explorer_analytical_components
10.0 ≤
𝑥
≤ 10.0.0.2
ibmwatson_explorer_analytical_components
11.0
ibmwatson_explorer_annotation_administration_console
10.0 ≤
𝑥
≤ 10.0.0.2
ibmwatson_explorer_annotation_administration_console
11.0
ibmwebsphere_application_server
7.0.0.0
ibmwebsphere_application_server
8.0.0.0
ibmwebsphere_application_server
8.5
ibmwebsphere_application_server
8.5.0.0
ibmwebsphere_application_server
8.5.5.5
𝑥
= Vulnerable software versions