vulnerability
Red Hat OpenShift: CVE-2015-7501: apache-commons-collections: InvokerTransformer code execution during deserialisation
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Nov 9, 2017 | Oct 8, 2019 | Apr 23, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Nov 9, 2017
Added
Oct 8, 2019
Modified
Apr 23, 2025
Description
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Solution
linuxrpm-upgrade-jenkins
References
- CVE-2015-7501
- https://attackerkb.com/topics/CVE-2015-7501
- REDHAT-RHSA-2015:2500
- REDHAT-RHSA-2015:2501
- REDHAT-RHSA-2015:2502
- REDHAT-RHSA-2015:2514
- REDHAT-RHSA-2015:2516
- REDHAT-RHSA-2015:2517
- REDHAT-RHSA-2015:2521
- REDHAT-RHSA-2015:2522
- REDHAT-RHSA-2015:2523
- REDHAT-RHSA-2015:2524
- REDHAT-RHSA-2015:2534
- REDHAT-RHSA-2015:2535
- REDHAT-RHSA-2015:2536
- REDHAT-RHSA-2015:2537
- REDHAT-RHSA-2015:2538
- REDHAT-RHSA-2015:2539
- REDHAT-RHSA-2015:2540
- REDHAT-RHSA-2015:2541
- REDHAT-RHSA-2015:2542
- REDHAT-RHSA-2015:2547
- REDHAT-RHSA-2015:2548
- REDHAT-RHSA-2015:2556
- REDHAT-RHSA-2015:2557
- REDHAT-RHSA-2015:2559
- REDHAT-RHSA-2015:2560
- REDHAT-RHSA-2015:2578
- REDHAT-RHSA-2015:2579
- REDHAT-RHSA-2015:2670
- REDHAT-RHSA-2015:2671
- REDHAT-RHSA-2016:0040
- REDHAT-RHSA-2016:0118
- REDHAT-RHSA-2016:1773

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.