EXPOSURES › CVE-2015-7450
CVE-2015-7450
HIGH ⌖ ON CISA KEV · EXPLOITEDRemote attackers could execute arbitrary commands via serialized-object interfaces in IBM WebSphere Application Server and Server Hypervisor Edition.
This code injection vulnerability allowed remote attackers to run arbitrary commands on systems running IBM WebSphere Application Server and Server Hypervisor Edition. DIB organizations must care because unpatched instances of this CVE are actively exploited in the wild, creating a direct path for ransomware or data exfiltration. Organizations should verify their WebSphere versions and apply patches immediately to prevent remote code execution.
Shame score — A known code injection flaw in a widely deployed enterprise server was left unpatched long enough to be added to CISA's KEV catalog, indicating negligent patch management and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |