CVE-2015-7450

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_integrator:5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_explorer_analytical_components:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_explorer_analytical_components:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:hypervisor:*:*:*

History

12 Feb 2025, 19:25

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-502

28 Jan 2025, 18:49

Type Values Removed Values Added
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21970575 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21970575 - Vendor Advisory
References (SECTRACK) http://www.securitytracker.com/id/1035125 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1035125 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21972799 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21972799 - Vendor Advisory
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/41613/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/41613/ - Exploit, Third Party Advisory, VDB Entry
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971733 - Broken Link () http://www-01.ibm.com/support/docview.wss?uid=swg21971733 - Broken Link
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971376 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21971376 - Vendor Advisory
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971758 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21971758 - Vendor Advisory
References (BID) http://www.securityfocus.com/bid/77653 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/77653 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971342 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21971342 - Vendor Advisory

24 Jul 2024, 17:02

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:watson_explorer_analytical_components:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:hypervisor:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:watson_explorer_analytical_components:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_integrator:5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:-:*:*:*
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:-:*:*:*
CWE CWE-94 NVD-CWE-noinfo
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/41613/ - (EXPLOIT-DB) https://www.exploit-db.com/exploits/41613/ - Exploit, Third Party Advisory, VDB Entry
References (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971733 - Vendor Advisory (CONFIRM) http://www-01.ibm.com/support/docview.wss?uid=swg21971733 - Broken Link
References (BID) http://www.securityfocus.com/bid/77653 - (BID) http://www.securityfocus.com/bid/77653 - Broken Link, Third Party Advisory, VDB Entry
References (SECTRACK) http://www.securitytracker.com/id/1035125 - (SECTRACK) http://www.securitytracker.com/id/1035125 - Broken Link, Third Party Advisory, VDB Entry
First Time Ibm watson Explorer Annotation Administration Console
Ibm watson Content Analytics
Ibm sterling B2b Integrator
Ibm websphere Application Server
Ibm sterling Integrator
Ibm watson Explorer Analytical Components

Information

Published : 2016-01-02 21:59

Updated : 2025-02-12 19:25


NVD link : CVE-2015-7450

Mitre link : CVE-2015-7450


JSON object : View

Products Affected

ibm

  • websphere_application_server
  • sterling_integrator
  • watson_explorer_annotation_administration_console
  • tivoli_common_reporting
  • watson_explorer_analytical_components
  • watson_content_analytics
  • sterling_b2b_integrator
CWE
CWE-502

Deserialization of Untrusted Data