Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
Data Grid
Subscribe
Enterprise Linux
Subscribe
Jboss A-mq
Subscribe
Jboss Amq
Subscribe
Jboss Bpm Suite
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Data Grid
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Jboss Operations Network
Subscribe
Jboss Portal
Subscribe
Openshift
Subscribe
Rhel Software Collections
Subscribe
Subscription Asset Manager
Subscribe
Xpaas
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fjq5-5j5f-mvxh | Deserialization of Untrusted Data in Apache commons collections |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T07:51:28.224Z
Reserved: 2015-09-29T00:00:00
Link: CVE-2015-7501
No data.
Status : Deferred
Published: 2017-11-09T17:29:00.203
Modified: 2025-04-20T01:37:25.860
Link: CVE-2015-7501
OpenCVE Enrichment
No data.
Github GHSA