CVE-2015-7501
published 2017-11-09CVE-2015-7501: Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform…
PriorityP191critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
83.27%
99.6th percentile
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libcommons-collections3-java | < libcommons-collections3-java 3.2.2-1 (bookworm) | libcommons-collections3-java 3.2.2-1 (bookworm) |
| debian | libcommons-collections4-java | < libcommons-collections3-java 3.2.2-1 (bookworm) | libcommons-collections3-java 3.2.2-1 (bookworm) |
| redhat | data_grid | — | — |
| redhat | jboss_a-mq | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_data_virtualization | — | — |
| redhat | jboss_data_virtualization | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_server | — | — |
| redhat | jboss_fuse | — | — |
| redhat | jboss_fuse_service_works | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_portal | — | — |
| redhat | openshift | — | — |
| redhat | subscription_asset_manager | — | — |
| redhat | xpaas | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandjava -jar ysoserial-0.0.5-SNAPSHOT-all.jar CommonsCollections5 'touch /tmp/danger_zone' > gadget.bin↗
- →Alert on HTTP requests carrying the custom header 'JBoss-Remoting-Version: 22' and 'remotingContentType: remotingContentTypeNonString' combined with a binary (application/octet-stream) body to the ServerInvokerServlet endpoint — characteristic of remoting-based deserialization exploit traffic. ↗
- →On patched JBoss, a server response containing 'Deserialization of InvokerTransformer is not permitted' confirms the fix is active; absence of this message on the same endpoint indicates a vulnerable/unpatched instance. ↗
- →The root cause class is InvokerTransformer in Apache Commons Collections; monitor for deserialization of this class (e.g., via Java agent or serialization filter logs) as a direct indicator of CVE-2015-7501 exploitation. ↗
- →JBoss EAP 5 is exploitable via the http-invoker.sar component's doFilter method in ReadOnlyAccessFilter; monitor HTTP traffic to this component for serialized object payloads. ↗
- →ysoserial CommonsCollections gadget chains (e.g., CommonsCollections5) are the primary weaponization vehicle; scan for ysoserial-generated payloads in HTTP POST bodies to JBoss remoting endpoints. ↗
- ·The vulnerable endpoint /jboss-remoting-servlet-invoker/ServerInvokerServlet accepts unauthenticated deserialization requests; the attack surface exists only when this servlet is publicly accessible. ↗
- ·Simply updating Apache Commons Collections is insufficient mitigation; other libraries on the classpath may provide alternative gadget chains for deserialization attacks. ↗
- ·The flaw in Fuse 6.2.0 and A-MQ 6.2.0 is rated Important (not Critical) because it is not known to be exploitable under supported scenarios in those specific product versions. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_oracle8.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Commons Collections) — CVE-2015-7501
vendor_oracle·2020-07-15·CVSS 8.8
CVE-2015-7501 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Commons Collections) — CVE-2015-7501
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Commons Collections) vulnerability
CVE: CVE-2015-7501
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
apache-commons-collections: InvokerTransformer code execution during deserialisation
vendor_redhat·2015-11-06·CVSS 9.8
CVE-2015-7501 [CRITICAL] CWE-502 apache-commons-collections: InvokerTransformer code execution during deserialisation
apache-commons-collections: InvokerTransformer code execution during deserialisation
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker co
Debian
CVE-2015-7501: libcommons-collections3-java - Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) ...
vendor_debian·2015·CVSS 9.8
CVE-2015-7501 [CRITICAL] CVE-2015-7501: libcommons-collections3-java - Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) ...
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Scope: local
bookworm: resolved (fixed in 3.2.2-1)
bullseye: resolved (fixed in 3.2.2-1)
forky: resolved (fixed in 3.2.2-1)
sid: resolved (fixed in 3.2.2-1)
trixie: resolved (fixed in 3.2.2-1)
OSV
Deserialization of Untrusted Data in Apache commons collections
osv·2022-05-13
CVE-2015-7501 [CRITICAL] Deserialization of Untrusted Data in Apache commons collections
Deserialization of Untrusted Data in Apache commons collections
It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.
GHSA
Deserialization of Untrusted Data in Apache commons collections
ghsa·2022-05-13
CVE-2015-7501 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Apache commons collections
Deserialization of Untrusted Data in Apache commons collections
It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.
OSV
CVE-2015-7501: Red Hat JBoss A-MQ 6
osv·2017-11-09·CVSS 9.8
CVE-2015-7501 [CRITICAL] CVE-2015-7501: Red Hat JBoss A-MQ 6
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
VulnCheck
Red Hat data_grid Deserialization of Untrusted Data
vulncheck·2015·CVSS 9.8
CVE-2015-7501 [CRITICAL] Red Hat data_grid Deserialization of Untrusted Data
Red Hat data_grid Deserialization of Untrusted Data
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Affected: Red Hat data_grid
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: htt
No detection rules found.
No public exploits indexed.
Tenable
May Vulnerability of the Month: Java Deserialization Everywhere
blogs_tenable·2018-05-18·CVSS 9.8
[CRITICAL] May Vulnerability of the Month: Java Deserialization Everywhere
Blog / Research
Subscribe
# May Vulnerability of the Month: Java Deserialization Everywhere
Tenable Research
May 18, 2018
3 Min Read
Every month, we ask our researchers to nominate a vulnerability of the month. Novelty, sophistication or just plain weirdness are some of the potential criteria for selecting a vulnerability of the month. After the nominations are collected, the candidates are shortlisted and voted on by our 70-plus-member research organization, combining the total experience and knowledge of Tenable Research to identify the vulnerability of the month.
### Background
On the heels of a failed patch to another Java deserialization vulnerability in Oracle WebLogic Servers, the research team voted to highlight a Red Hat JBoss vulnerability this month. CVE-2017-12149 is ano
Tenable
May Vulnerability of the Month: Java Deserialization Everywhere
blogs_tenable·2018-05-18
May Vulnerability of the Month: Java Deserialization Everywhere
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Expanding on a Known Vulnerability: Attacking with Jython
blogs_tenable·2016-09-07·CVSS 9.8
CVE-2016-3737 [CRITICAL] Expanding on a Known Vulnerability: Attacking with Jython
Blog /
Subscribe
# Expanding on a Known Vulnerability: Attacking with Jython
Jacob Baines
September 7, 2016
24 Min Read
As a Reverse Engineer at Tenable, I investigate disclosed vulnerabilities in order to write remote plugins for the Nessus® vulnerability scanner. Each investigation is unique and presents its own set of challenges. In some cases, new vulnerabilities are uncovered. One such investigation happened earlier this year when I was analyzing CVE-2016-3737 in Red Hat JBoss Operations Network (JON).
When I began looking into CVE-2016-3737, the entry in the National Vulnerability Database was empty but there was a Red Hat security advisory that read:
> It was discovered that sending specially crafted HTTP request to the JON server would allow deserialization of that message w
Tenable
Expanding on a Known Vulnerability: Attacking with Jython
blogs_tenable·2016-09-07
Expanding on a Known Vulnerability: Attacking with Jython
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2016-3690 PooledInvokerServlet is not secured, and deserializes data
bugzilla·2016-04-14·CVSS 9.8
CVE-2016-3690 [CRITICAL] CVE-2016-3690 PooledInvokerServlet is not secured, and deserializes data
CVE-2016-3690 PooledInvokerServlet is not secured, and deserializes data
The HA Pooled Invoker allows unauthorised access, and deserializes any payload sent to it.
This is one of the attack vectors for CVE-2015-7501. There are many new gadget chains available in the ysoserial project. For example the Beanshell library could be used to create a malicious serialized object. When deserialized by the HA Pooled Invoker servlet allows remote code execution.
Discussion:
Acknowledgments:
Name: Dennis Reed (Red Hat)
---
Any KCS already published on the topic: https://access.redhat.com/solutions/45530
---
Need to update Installation Guides with WARNING about unsecured Invokers, and linked to the KCS Solution 45530
---
Mitigation:
The PooledInvokerServlet is no longer required and can be
Bugzilla
CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
bugzilla·2015-12-18·CVSS 8.1
CVE-2015-5348 [HIGH] CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
A flaw was found in Apache Camel:
Apache Camel's Jetty/Servlet usage is vulnerable to Java object de-serialisation vulnerability
If using camel-jetty, or camel-servlet as a consumer in Camel routes, then Camel will automatic de-serialize HTTP requests that uses the content-header: application/x-java-serialized-object.
External References:
https://camel.apache.org/security-advisories.data/CVE-2015-5348.txt
Discussion:
Tracker for Fuse 6.2.1: https://issues.jboss.org/browse/ENTESB-4744
---
Tracker for A-MQ 6.2.1: https://issues.jboss.org/browse/ENTMQ-1464
---
CVE-2015-5348 is currently scheduled to be fixed in the Fuse 6.3 release. It is ranked as having moderate impact, so we feel it's not worthy of including in a
Bugzilla
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
bugzilla·2015-11-09·CVSS 6.8
CVE-2015-7501 [MEDIUM] CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
It was found that a flaw in commons-collection library allowed remote code execution wherever deserialization occurs. While JBoss doesnt expose the JMXInvokerServlet by default, other interfaces where deserialization occur might be vulnerable.
Note: classes directly referenced by this flaw:
InvokerTransformer, InstantiateFactory, and InstantiateTransformer
External References:
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
https://access.redhat.com/solutions/2045023
Discussion:
This was addressed back in 2012:
https://access.redhat.com/security/cve/CVE-2012-0874
While we have the JMXInvoke
http://rhn.redhat.com/errata/RHSA-2015-2500.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2501.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2502.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2514.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2516.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2517.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2521.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2522.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2524.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2670.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2671.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/78215http://www.securitytracker.com/id/1034097http://www.securitytracker.com/id/1037052http://www.securitytracker.com/id/1037053http://www.securitytracker.com/id/1037640https://access.redhat.com/security/vulnerabilities/2059393https://access.redhat.com/solutions/2045023https://bugzilla.redhat.com/show_bug.cgi?id=1279330https://rhn.redhat.com/errata/RHSA-2015-2536.htmlhttps://security.netapp.com/advisory/ntap-20240216-0010/https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2500.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2501.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2502.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2514.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2516.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2517.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2521.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2522.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2524.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2670.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2671.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/78215http://www.securitytracker.com/id/1034097http://www.securitytracker.com/id/1037052http://www.securitytracker.com/id/1037053http://www.securitytracker.com/id/1037640https://access.redhat.com/security/vulnerabilities/2059393https://access.redhat.com/solutions/2045023https://bugzilla.redhat.com/show_bug.cgi?id=1279330https://rhn.redhat.com/errata/RHSA-2015-2536.htmlhttps://security.netapp.com/advisory/ntap-20240216-0010/https://www.oracle.com/security-alerts/cpujul2020.html
2017-11-09
Published
Exploited in the wild