Vulnerability record · CVE-2015-7450 · published 2 January 2016
CVE-2015-7450: IBM products Java deserialization RCE via Commons Collections
Ibm · Sterling B2b Integrator
Multiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java objects, allowing remote command execution through the Apache Commons Collections InvokerTransformer gadget chain. The flaw is remotely reachable without authentication and affects widely deployed IBM middleware, making it a high-value target for initial access.
Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed, near-maximum EPSS, and public exploit code make this an actively targeted unauthenticated RCE.
What it is
Multiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java objects, allowing remote command execution through the Apache Commons Collections InvokerTransformer gadget chain. The flaw is remotely reachable without authentication and affects widely deployed IBM middleware, making it a high-value target for initial access.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the affected server, leading to full compromise of confidentiality, integrity, and availability.
Attack surface
Reached over the network via serialized-object interfaces exposed by the affected IBM products; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
CVE-2015-7450 is listed in CISA KEV (added 2022-01-10) and has an EPSS 30-day probability of 0.97655 (99.9th percentile); a public Exploit-DB entry exists, and KEV notes no known ransomware campaign use.
What to do
- Apply the IBM vendor updates referenced in the advisories (swg21970575, swg21971342, swg21971376, swg21971758, swg21972799) as the first action.
- Where patching is delayed, restrict network access to serialized-object endpoints and management interfaces to trusted hosts only.
- Upgrade or remove vulnerable Apache Commons Collections versions and apply Java deserialization filters (e.g., JEP 290-style allowlists) where supported.
- Monitor and alert on deserialization-related exceptions and unexpected child processes spawned by Java application servers.
Detection
- Inspect Java application server logs for deserialization exceptions and InvokerTransformer or Commons Collections gadget class references.
- Alert on unexpected process creation (cmd.exe, /bin/sh, powershell) with a Java parent process on affected hosts.
- Monitor network traffic to serialized-object endpoints for anomalous or oversized serialized payloads.
- Hunt for outbound connections from affected IBM servers to unusual destinations following deserialization activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-7450 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.". Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7450 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7450), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.