PT-2015-3347 · Red Hat+3 · Red Hat Fuse+17

Published

2015-11-06

·

Updated

2026-05-19

·

CVE-2015-7501

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat JBoss A-MQ versions 6.x Red Hat BPM Suite (BPMS) versions 6.x Red Hat BRMS versions 5.x and 6.x Red Hat Data Grid (JDG) versions 6.x Red Hat Data Virtualization (JDV) versions 5.x and 6.x Red Hat Enterprise Application Platform versions 4.3.x, 5.x, and 6.x Red Hat Fuse versions 6.x Red Hat Fuse Service Works (FSW) versions 6.x Red Hat Operations Network (JBoss ON) versions 3.x Red Hat Portal versions 6.x Red Hat SOA Platform (SOA-P) versions 5.x Red Hat Web Server (JWS) versions 3.x Red Hat OpenShift/xPAAS versions 3.x Red Hat Subscription Asset Manager version 1.3
Description The issue is related to the Apache Commons Collections (ACC) library, which allows remote attackers to execute arbitrary commands via a crafted serialized Java object. This can be achieved by exploiting a flaw in the library that permits code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.
Recommendations For Red Hat JBoss A-MQ versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat BPM Suite (BPMS) versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat BRMS versions 5.x and 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Data Grid (JDG) versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Data Virtualization (JDV) versions 5.x and 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Enterprise Application Platform versions 4.3.x, 5.x, and 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Fuse versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Fuse Service Works (FSW) versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Operations Network (JBoss ON) versions 3.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Portal versions 6.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat SOA Platform (SOA-P) versions 5.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Web Server (JWS) versions 3.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat OpenShift/xPAAS versions 3.x, update to a version that includes the fix for the Apache Commons Collections library issue. For Red Hat Subscription Asset Manager version 1.3, update to a version that includes the fix for the Apache Commons Collections library issue.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2017-02651
CESA-2015_2521
CESA-2015_2522
CVE-2015-7501
ELSA-2015-2521
ELSA-2015-2522
GHSA-FJQ5-5J5F-MVXH
MGASA-2016-0012
RHSA-2015:2500
RHSA-2015:2521
RHSA-2015:2522
RHSA-2015:2523
RHSA-2015:2535
RHSA-2015:2536
RHSA-2015:2538
RHSA-2015:2539
RHSA-2015:2540
RHSA-2015:2542
RHSA-2015:2671
RHSA-2015_2521
RHSA-2015_2522
RHSA-2015_2671
RHSA-2016:1773
RHSA-2020:4274

Affected Products

Apache Commons Collections
Centos
Debian
Red Hat
Red Hat Bpm Suite
Red Hat Brms
Red Hat Datagrid
Red Hat Data Virtualization
Red Hat Jboss Enterprise Application Platform
Red Hat Fuse
Red Hat Fuse Service Works
Red Hat Jboss A-Mq
Red Hat Openshift/Xpaas
Red Hat Operations Network
Red Hat Portal
Red Hat Soa Platform
Red Hat Subscription Asset Manager
Red Hat Web Server