Vulnerability Intelligence Report
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:97.66%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502 Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_integrator | 5.1 |
| ibm | tivoli_common_reporting | 2.1, 2.1.1, 2.1.1.2, 3.1, 3.1.0.1, 3.1.0.2, 3.1.2, 3.1.2.1 |
| ibm | watson_content_analytics | all |
| ibm | watson_explorer_analytical_components | 11.0 |
| ibm | watson_explorer_annotation_administration_console | 11.0 |
| ibm | websphere_application_server | 7.0.0.0, 8.0.0.0, 8.5, 8.5.0.0, 8.5.5.5 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
97.655%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | IBM Corporation · Vendor · USA |
| Reserved | 2015-09-29T00:00:00 |
| Published | 2016-01-02T21:00:00 |
| Patch Date | 2015-12-10 |
| Last Updated | 2025-10-21T23:55:56 |
Community Chatter & Buzz