CVE-2015-7450

CRITICAL KEV NUCLEI

IBM Sterling B2B Integrator - Remote Code Execution via Apache Commons Collections Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-7450 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 10, 2022. EIP tracks 3 public exploits from researchers including Metasploit, Liatsis Fotios @liatsisfotios, including a Metasploit module exploits/windows/misc/ibm_websphere_java_deserialize. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests.

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/41613

This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM WebSphere Application Server 7.0.0.0
No auth needed
Prerequisites: Network access to IBM WebSphere SOAP endpoint · Vulnerable version of IBM WebSphere
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb WRITEUP
remote
https://github.com/swisskyrepo/PayloadsAllTheThings

This repository contains a detailed technical writeup on IIS Machine Keys and ViewState manipulation, including formats, locations, and tools for identification and exploitation. It does not include functional exploit code but provides in-depth analysis and references for CVE-2015-7450.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft IIS with ASP.NET ViewState
No auth needed
Prerequisites: Access to ViewState data · Knowledge of machine key or ability to brute-force
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Liatsis Fotios @liatsisfotios · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_websphere_java_deserialize.rb

This Metasploit module exploits CVE-2015-7450, an unsafe Java deserialization vulnerability in IBM WebSphere Application Server, allowing unauthenticated remote code execution via crafted SOAP requests containing malicious serialized objects.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM WebSphere Application Server 7.0.0.0
No auth needed
Prerequisites: Network access to the target WebSphere server · SOAP endpoint exposed on port 8880
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

IBM WebSphere Java Object Deserialization - Remote Code Execution
CRITICALby wdahlenb
Shodan: http.html:"IBM WebSphere Portal" || http.html:"ibm websphere portal"
FOFA: body="ibm websphere portal"

References (10)

Core 10
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971342
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971758
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77653
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035125
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21972799
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971376
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41613/
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21970575

Scores

CVSS v3 9.8
EPSS 0.9327
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-01-10
VulnCheck KEV 2021-01-05
InTheWild.io 2022-01-10
ENISA EUVD EUVD-2015-7374
CWE
CWE-502
Status published
Products (20)
ibm/sterling_b2b_integrator 5.2
ibm/sterling_integrator 5.1
ibm/tivoli_common_reporting 2.1
ibm/tivoli_common_reporting 2.1.1
ibm/tivoli_common_reporting 2.1.1.2
ibm/tivoli_common_reporting 3.1
ibm/tivoli_common_reporting 3.1.0.1
ibm/tivoli_common_reporting 3.1.0.2
ibm/tivoli_common_reporting 3.1.2
ibm/tivoli_common_reporting 3.1.2.1
... and 10 more
Published Jan 02, 2016
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026