CVE-2015-7450
CRITICAL KEV NUCLEIIBM Sterling B2B Integrator - Remote Code Execution via Apache Commons Collections Deserialization
Title source: llmExploitation Summary
CVE-2015-7450 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 10, 2022.
EIP tracks 3 public exploits from researchers including Metasploit, Liatsis Fotios @liatsisfotios, including a Metasploit module exploits/windows/misc/ibm_websphere_java_deserialize.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests.
Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Exploits (3)
This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests.
This repository contains a detailed technical writeup on IIS Machine Keys and ViewState manipulation, including formats, locations, and tools for identification and exploitation. It does not include functional exploit code but provides in-depth analysis and references for CVE-2015-7450.
This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests containing malicious serialized objects.
Nuclei Templates (1)
http.html:"IBM WebSphere Portal" || http.html:"ibm websphere portal"
body="ibm websphere portal"
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H