CVE-2015-7450
published 2016-01-02CVE-2015-7450: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers…
PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-10
Exploited in the wild
EPSS
97.66%
99.9th percentile
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_integrator | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | tivoli_common_reporting | — | — |
| ibm | watson_content_analytics | 3.0 – 3.0.0.6 | — |
| ibm | watson_content_analytics | 3.5 – 3.5.0.3 | — |
| ibm | watson_explorer_analytical_components | — | — |
| ibm | watson_explorer_analytical_components | 10.0 – 10.0.0.2 | — |
| ibm | watson_explorer_annotation_administration_console | — | — |
| ibm | watson_explorer_annotation_administration_console | 10.0 – 10.0.0.2 | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
othershodan: http.html:"IBM WebSphere Portal"
otherfofa: body="ibm websphere portal"
snort
alert tcp $EXTERNAL_NET any -> $HOME_NET 8880 (msg:"ET EXPLOIT IBM WebSphere - RCE Java Deserialization"; flow:established,to_server; content:"SOAPAction|3a 20||22|urn:AdminService|22|"; content:""; content:"vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn"; fast_pattern; reference:cve,2015-7450; classtype:attempted-user; sid:2024062; rev:4; metadata:affected_product IBM_Websphere, attack_target Server, created_at 2017_03_15, cve CVE_2015_7450, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2024_03_07;)
bytes
vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn
bytes↗
rO0ABXNyADJzdW4ucmVmbGVjdC5hbm5vdGF0aW9uLkFubm90YXRpb25JbnZvY2F0aW9uSGFuZGxlclXK9Q8Vy36lAgACTAAMbWVtYmVyVmFsdWVzdAAPTGphdmEvdXRpbC9NYXA7TAAEdHlwZXQAEUxqYXZhL2xhbmcvQ2xhc3M7eHBzfQAAAAEADWphdmEudXRpbC5NYXB4cgAXamF2YS5sYW5nLnJlZmxlY3QuUHJveHnhJ9ogzBBDywIAAUwAAWh0ACVMamF2YS9sYW5nL3JlZmxlY3QvSW52b2NhdGlvbkhhbmRsZXI7eHBzcQB+AABzcgAqb3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLm1hcC5MYXp5TWFwbuWUgp55EJQDAAFMAAdmYWN0b3J5dAAsTG9yZy9hcGFjaGUvY29tbW9ucy9jb2xsZWN0aW9ucy9UcmFuc2Zvcm1lcjt4cHNyADpvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuZnVuY3RvcnMuQ2hhaW5lZFRyYW5zZm9ybWVyMMeX7Ch6lwQCAAFbAA1pVHJhbnNmb3JtZXJzdAAtW0xvcmcvYXBhY2hlL2NvbW1vbnMvY29sbGVjdGlvbnMvVHJhbnNmb3JtZXI7eHB1cgAtW0xvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuVHJhbnNmb3JtZXI7vVYq8dg0GJkCAAB4cAAAAAVzcgA7b3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLmZ1bmN0b3JzLkNvbnN0YW50VHJhbnNmb3JtZXJYdpARQQKxlAIAAUwACWlDb25zdGFudHQAEkxqYXZhL2xhbmcvT2JqZWN0O3hwdnIAEWphdmEubGFuZy5SdW50aW1lAAAAAAAAAAAAAAB4cHNyADpvcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbnMuZnVuY3RvcnMuSW52b2tlclRyYW5zZm9ybWVyh+j/a3t8zjgCAANbAAVpQXJnc3QAE1tMamF2YS9sYW5nL09iamVjdDtMAAtpTWV0aG9kTmFtZXQAEkxqYXZhL2xhbmcvU3RyaW5nO1sAC2lQYXJhbVR5cGVzdAASW0xqYXZhL2xhbmcvQ2xhc3M7eHB1cgATW0xqYXZhLmxhbmcuT2JqZWN0O5DOWJ8QcylsAgAAeHAAAAACdAAKZ2V0UnVudGltZXVyABJbTGphdmEubGFuZy5DbGFzczurFteuy81amQIAAHhwAAAAAHQACWdldE1ldGhvZHVxAH4AHgAAAAJ2cgAQamF2YS5sYW5nLlN0cmluZ6DwpDh6O7NCAgAAeHB2cQB+AB5zcQB+ABZ1cQB+ABsAAAACcHVxAH4AGwAAAAB0AAZpbnZva2V1cQB+AB4AAAACdnIAEGphdmEubGFuZy5PYmplY3QAAAAAAAAAAAAAAHhwdnEAfgAbc3EAfgAWdXIAE1tMamF2YS5sYW5nLlN0cmluZzut0lbn6R17RwIAAHhwAAAAAXQ=
bytes
rO0ABXVyABNbTGphdmEubGFuZy5TdHJpbmc7rdJW5+kde0cCAAB4cAAAAAF0ACRjb20uaWJtLndlYnNwaGVyZS5tYW5hZ2VtZW50LlNlc3Npb24=
- →Exploit traffic targets TCP port 8880 (IBM WebSphere SOAP Connector) with an HTTP POST containing the SOAPAction header value 'urn:AdminService' and a base64-encoded serialized Java payload in the SOAP body.
- →The serialized payload stream begins with the Java serialization magic bytes 'rO0AB' (base64 of 0xACED0000) and contains the string 'vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn' (base64 fragment for 'org.apache.commons.collections'), which is the fast_pattern anchor used in the ET Snort rule.
- →A server response of HTTP 500 containing both 'SOAP-ENV:Server' and '' is a positive indicator of a vulnerable IBM WebSphere endpoint that processed the malicious deserialization request.
- →FIN13 (Elephant Beetle) has been observed actively exploiting CVE-2015-7450 (WebSphere Application Server SOAP Deserialization) for initial access against financial, retail, and hospitality targets in Mexico and Latin America.
- →The exploit requires no authentication; any unauthenticated POST to the WebSphere SOAP endpoint on port 8880 carrying a serialized Java object payload should be treated as suspicious. ↗
- ·The Nuclei template uses an OOB DNS interaction (interactsh) to confirm exploitation; a DNS callback from the target confirms the vulnerability is present even if no direct shell is returned.
- ·The ET Snort rule (sid:2024062) is scoped to inbound traffic on port 8880 only; deployments where WebSphere SOAP is exposed on a non-standard port will not be covered by this rule without modification.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer code injection (EDB-41613 / Nessus ID 87171)
vuldb·2026-04-23·CVSS 9.8
CVE-2015-7450 [CRITICAL] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer code injection (EDB-41613 / Nessus ID 87171)
A vulnerability marked as critical has been reported in IBM Cognos Business Intelligence. Affected is the function InvokerTransformer of the component Apache Commons Collections Library. This manipulation causes code injection.
This vulnerability is registered as CVE-2015-7450. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-8987-qgc7-79p9: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote a
ghsa_unreviewed·2022-05-17
CVE-2015-7450 [CRITICAL] CWE-502 GHSA-8987-qgc7-79p9: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote a
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
VulnCheck
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
vulncheck·2015·CVSS 9.8
CVE-2015-7450 [CRITICAL] CWE-94 IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
Affected: IBM WebSphere Application Server and Server Hypervisor Edition
Required Action: Apply updates per vendor instructions.
Exploitation References: https://f.hubspotusercontent30.net/hubfs/8776530/Sygnia-%20Elephant%20Beetle_Jan2022.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF
Exploit PoC: https://vulncheck.com/xdb/322395a3fefa
Remediation Due: 2022-07-10
CISA
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
cisa·2022-01-10·CVSS 9.8
CVE-2015-7450 [CRITICAL] CWE-94 IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Vulnerability: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Affected: IBM WebSphere Application Server and Server Hypervisor Edition
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-7450
Remediation Due Date: 2022-07-10
Suricata
ET EXPLOIT IBM WebSphere - RCE Java Deserialization
suricata·2017-03-15
CVE-2015-7450 ET EXPLOIT IBM WebSphere - RCE Java Deserialization
ET EXPLOIT IBM WebSphere - RCE Java Deserialization
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 8880 (msg:"ET EXPLOIT IBM WebSphere - RCE Java Deserialization"; flow:established,to_server; content:"SOAPAction|3a 20||22|urn:AdminService|22|"; content:""; content:"vcmcuYXBhY2hlLmNvbW1vbnMuY29sbGVjdGlvbn"; fast_pattern; reference:cve,2015-7450; classtype:attempted-user; sid:2024062; rev:4; metadata:affected_product IBM_Websphere, attack_target Server, created_at 2017_03_15, cve CVE_2015_7450, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2024_03_07;)
Exploit-DB
IBM WebSphere - RCE Java Deserialization (Metasploit)
exploitdb·2017-03-15
CVE-2015-7450 IBM WebSphere - RCE Java Deserialization (Metasploit)
IBM WebSphere - RCE Java Deserialization (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule "IBM WebSphere RCE Java Deserialization Vulnerability",
'Description' => %q{
This module exploits a vulnerability in IBM's WebSphere Application Server. An unsafe deserialization
call of unauthenticated Java objects exists to the Apache Commons Collections (ACC) library, which allows
remote arbitrary code execution. Authentication is not required in order to exploit this vulnerability.
},
'License' => MSF_LICENSE,
'Author' =>
[
'Liatsis Fotios @liatsisfotios' # Metasploit Module
# Thanks for helping me:
# # # # # # # # # # # #
# Kyprianos Vasilopoulos
Nuclei
IBM WebSphere Java Object Deserialization - Remote Code Execution
nuclei·CVSS 9.8
CVE-2015-7450 [CRITICAL] IBM WebSphere Java Object Deserialization - Remote Code Execution
IBM WebSphere Java Object Deserialization - Remote Code Execution
IBM Websphere Application Server 7, 8, and 8.5 have a deserialization vulnerability in the SOAP Connector (port 8880 by default).
Template:
id: CVE-2015-7450
info:
name: IBM WebSphere Java Object Deserialization - Remote Code Execution
author: wdahlenb
severity: critical
description: IBM Websphere Application Server 7, 8, and 8.5 have a deserialization vulnerability in the SOAP Connector (port 8880 by default).
impact: |
Successful exploitation of this vulnerability can lead to remote code execution, allowing an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches provided by IBM to mitigate this vulnerability.
reference:
- https://github.com/Coalfire-Research/java-d
Metasploit
IBM WebSphere RCE Java Deserialization Vulnerability
metasploit
IBM WebSphere RCE Java Deserialization Vulnerability
IBM WebSphere RCE Java Deserialization Vulnerability
This module exploits a vulnerability in IBM's WebSphere Application Server. An unsafe deserialization call of unauthenticated Java objects exists to the Apache Commons Collections (ACC) library, which allows remote arbitrary code execution. Authentication is not required in order to exploit this vulnerability.
Threat Intel
FIN13 (FIN13, Elephant Beetle)
threat_intel·CVSS 10.0
[CRITICAL] FIN13 (FIN13, Elephant Beetle)
# Threat Actor Profile: FIN13
ATT&CK ID: G1016
Also known as: FIN13, Elephant Beetle
## Overview
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)
## Techniques (TTPs)
### Reconnaissance
- T1589 Gather Victim Identity Information
Usage: FIN13 has researched employees to target for social engineering attacks.(Citation: Mandiant FIN13 Aug 2022)
- T1590.004 Network Topology
Usage: FIN13 has searched for infrastructure that can provide remote access to an environment for targ
http://www-01.ibm.com/support/docview.wss?uid=swg21970575http://www-01.ibm.com/support/docview.wss?uid=swg21971342http://www-01.ibm.com/support/docview.wss?uid=swg21971376http://www-01.ibm.com/support/docview.wss?uid=swg21971733http://www-01.ibm.com/support/docview.wss?uid=swg21971758http://www-01.ibm.com/support/docview.wss?uid=swg21972799http://www.securityfocus.com/bid/77653http://www.securitytracker.com/id/1035125https://www.exploit-db.com/exploits/41613/http://www-01.ibm.com/support/docview.wss?uid=swg21970575http://www-01.ibm.com/support/docview.wss?uid=swg21971342http://www-01.ibm.com/support/docview.wss?uid=swg21971376http://www-01.ibm.com/support/docview.wss?uid=swg21971733http://www-01.ibm.com/support/docview.wss?uid=swg21971758http://www-01.ibm.com/support/docview.wss?uid=swg21972799http://www.securityfocus.com/bid/77653http://www.securitytracker.com/id/1035125https://www.exploit-db.com/exploits/41613/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-7450
2016-01-02
Published
2022-01-10
Added to CISA KEV
Exploited in the wild