cbcvebase.
CVE-2015-7450
published 2016-01-02

CVE-2015-7450: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers…

PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-10
Exploited in the wild
EPSS
97.66%
99.9th percentile
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Affected

21 ranges
VendorProductVersion rangeFixed in
ibmsterling_b2b_integrator
ibmsterling_integrator
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmtivoli_common_reporting
ibmwatson_content_analytics3.0 – 3.0.0.6
ibmwatson_content_analytics3.5 – 3.5.0.3
ibmwatson_explorer_analytical_components
ibmwatson_explorer_analytical_components10.0 – 10.0.0.2
ibmwatson_explorer_annotation_administration_console
ibmwatson_explorer_annotation_administration_console10.0 – 10.0.0.2
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server

Detection & IOCsextracted from sources · hover to see the quote

port8880
commandSOAPAction: "urn:AdminService"
othershodan: http.html:"IBM WebSphere Portal"
otherfofa: body="ibm websphere portal"
snort
alert tcp $EXTERNAL_NET any -> $HOME_NET 8880 (msg:"ET EXPLOIT IBM WebSphere - RCE Java Deserialization"; flow:established,to_server; content:"SOAPAction|3a 20||22|urn:AdminService|22|"; content:""; content:"vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn"; fast_pattern; reference:cve,2015-7450; classtype:attempted-user; sid:2024062; rev:4; metadata:affected_product IBM_Websphere, attack_target Server, created_at 2017_03_15, cve CVE_2015_7450, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2024_03_07;)
bytes
vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn
bytes
rO0ABXNyADJzdW4ucmVmbGVjdC5hbm5vdGF0aW9uLkFubm90YXRpb25JbnZvY2F0aW9uSGFuZGxlclXK9Q8Vy36lAgACTAAMbWVtYmVyVmFsdWVzdAAPTGphdmEvdXRpbC9NYXA7TAAEdHlwZXQAEUxqYXZhL2xhbmcvQ2xhc3M7eHBzfQAAAAEADWphdmEudXRpbC5NYXB4cgAXamF2YS5sYW5nLnJlZmxlY3QuUHJveHnhJ9ogzBBDywIAAUwAAWh0ACVMamF2YS9sYW5nL3JlZmxlY3QvSW52b2NhdGlvbkhhbmRsZXI7eHBzcQB+AABzcgAqb3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLm1hcC5MYXp5TWFwbuWUgp55EJQDAAFMAAdmYWN0b3J5dAAsTG9yZy9hcGFjaGUvY29tbW9ucy9jb2xsZWN0aW9ucy9UcmFuc2Zvcm1lcjt4cHNyADpvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuZnVuY3RvcnMuQ2hhaW5lZFRyYW5zZm9ybWVyMMeX7Ch6lwQCAAFbAA1pVHJhbnNmb3JtZXJzdAAtW0xvcmcvYXBhY2hlL2NvbW1vbnMvY29sbGVjdGlvbnMvVHJhbnNmb3JtZXI7eHB1cgAtW0xvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuVHJhbnNmb3JtZXI7vVYq8dg0GJkCAAB4cAAAAAVzcgA7b3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLmZ1bmN0b3JzLkNvbnN0YW50VHJhbnNmb3JtZXJYdpARQQKxlAIAAUwACWlDb25zdGFudHQAEkxqYXZhL2xhbmcvT2JqZWN0O3hwdnIAEWphdmEubGFuZy5SdW50aW1lAAAAAAAAAAAAAAB4cHNyADpvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuZnVuY3RvcnMuSW52b2tlclRyYW5zZm9ybWVyh+j/a3t8zjgCAANbAAVpQXJnc3QAE1tMamF2YS9sYW5nL09iamVjdDtMAAtpTWV0aG9kTmFtZXQAEkxqYXZhL2xhbmcvU3RyaW5nO1sAC2lQYXJhbVR5cGVzdAASW0xqYXZhL2xhbmcvQ2xhc3M7eHB1cgATW0xqYXZhLmxhbmcuT2JqZWN0O5DOWJ8QcylsAgAAeHAAAAACdAAKZ2V0UnVudGltZXVyABJbTGphdmEubGFuZy5DbGFzczurFteuy81amQIAAHhwAAAAAHQACWdldE1ldGhvZHVxAH4AHgAAAAJ2cgAQamF2YS5sYW5nLlN0cmluZ6DwpDh6O7NCAgAAeHB2cQB+AB5zcQB+ABZ1cQB+ABsAAAACcHVxAH4AGwAAAAB0AAZpbnZva2V1cQB+AB4AAAACdnIAEGphdmEubGFuZy5PYmplY3QAAAAAAAAAAAAAAHhwdnEAfgAbc3EAfgAWdXIAE1tMamF2YS5sYW5nLlN0cmluZzut0lbn6R17RwIAAHhwAAAAAXQ=
bytes
rO0ABXVyABNbTGphdmEubGFuZy5TdHJpbmc7rdJW5+kde0cCAAB4cAAAAAF0ACRjb20uaWJtLndlYnNwaGVyZS5tYW5hZ2VtZW50LlNlc3Npb24=
  • Exploit traffic targets TCP port 8880 (IBM WebSphere SOAP Connector) with an HTTP POST containing the SOAPAction header value 'urn:AdminService' and a base64-encoded serialized Java payload in the SOAP body.
  • The serialized payload stream begins with the Java serialization magic bytes 'rO0AB' (base64 of 0xACED0000) and contains the string 'vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn' (base64 fragment for 'org.apache.commons.collections'), which is the fast_pattern anchor used in the ET Snort rule.
  • A server response of HTTP 500 containing both 'SOAP-ENV:Server' and '' is a positive indicator of a vulnerable IBM WebSphere endpoint that processed the malicious deserialization request.
  • FIN13 (Elephant Beetle) has been observed actively exploiting CVE-2015-7450 (WebSphere Application Server SOAP Deserialization) for initial access against financial, retail, and hospitality targets in Mexico and Latin America.
  • The exploit requires no authentication; any unauthenticated POST to the WebSphere SOAP endpoint on port 8880 carrying a serialized Java object payload should be treated as suspicious.
  • ·The Nuclei template uses an OOB DNS interaction (interactsh) to confirm exploitation; a DNS callback from the target confirms the vulnerability is present even if no direct shell is returned.
  • ·The ET Snort rule (sid:2024062) is scoped to inbound traffic on port 8880 only; deployments where WebSphere SOAP is exposed on a non-standard port will not be covered by this rule without modification.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.