Skip to content
COOEY

EXPOSURES › CVE-2015-7450

CVE-2015-7450

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-7450 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Remote attackers could execute arbitrary commands via serialized-object interfaces in IBM WebSphere Application Server and Server Hypervisor Edition.

This code injection vulnerability allowed remote attackers to run arbitrary commands on systems running IBM WebSphere Application Server and Server Hypervisor Edition. DIB organizations must care because unpatched instances of this CVE are actively exploited in the wild, creating a direct path for ransomware or data exfiltration. Organizations should verify their WebSphere versions and apply patches immediately to prevent remote code execution.

Shame score — A known code injection flaw in a widely deployed enterprise server was left unpatched long enough to be added to CISA's KEV catalog, indicating negligent patch management and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized