Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7501

Опубликовано: 06 нояб. 2015
Источник: redhat
CVSS2: 7.5
EPSS Высокий

Описание

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.

Отчет

This issue affects the Apache commons-collections library as shipped with Fuse 6.2.0 and A-MQ 6.2.0. However, this flaw is not known to be exploitable under supported scenarios in these product versions, and so has been assigned an impact of Important for these products and their respective errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3jasperreports-server-proAffected
Red Hat JBoss A-MQ 6camelAffected
Red Hat JBoss Enterprise Application Platform 4jbossasAffected
Red Hat JBoss Enterprise Web Server 2tomcatNot affected
Red Hat JBoss Portal 5jbossasAffected
Red Hat JBoss SOA Platform 4JBossASAffected
Red Hat JBoss SOA Platform 5jbossasAffected
Red Hat OpenStack Platform 8 (Liberty)opendaylightNot affected
Red Hat Software Collectionsrh-maven35-apache-commons-collectionsNot affected
Red Hat Software Collectionsrh-maven36-apache-commons-collectionsNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502->CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1279330apache-commons-collections: InvokerTransformer code execution during deserialisation

EPSS

Процентиль: 99%
0.71461
Высокий

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS3: 9.8
nvd
почти 8 лет назад

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS3: 9.8
debian
почти 8 лет назад

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data G ...

CVSS3: 9.8
github
больше 3 лет назад

Deserialization of Untrusted Data in Apache commons collections

oracle-oval
больше 9 лет назад

ELSA-2015-2671: jakarta-commons-collections security update (IMPORTANT)

EPSS

Процентиль: 99%
0.71461
Высокий

7.5 High

CVSS2