← Vulnerability feed

Vulnerability record · CVE-2015-7450 · published 2 January 2016

CVE-2015-7450: IBM products Java deserialization RCE via Commons Collections

Ibm · Sterling B2b Integrator

Multiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java objects, allowing remote command execution through the Apache Commons Collections InvokerTransformer gadget chain. The flaw is remotely reachable without authentication and affects widely deployed IBM middleware, making it a high-value target for initial access.

9.8 CVSS 3.1 Critical CISA KEV since 10 Jan 2022 EPSS 98% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 10.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
19References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed, near-maximum EPSS, and public exploit code make this an actively targeted unauthenticated RCE.

What it is

Multiple IBM analytics, business, IT infrastructure, and mobile/social products expose serialized-object interfaces that deserialize untrusted Java objects, allowing remote command execution through the Apache Commons Collections InvokerTransformer gadget chain. The flaw is remotely reachable without authentication and affects widely deployed IBM middleware, making it a high-value target for initial access.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the affected server, leading to full compromise of confidentiality, integrity, and availability.

Attack surface

Reached over the network via serialized-object interfaces exposed by the affected IBM products; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

CVE-2015-7450 is listed in CISA KEV (added 2022-01-10) and has an EPSS 30-day probability of 0.97655 (99.9th percentile); a public Exploit-DB entry exists, and KEV notes no known ransomware campaign use.

What to do

  • Apply the IBM vendor updates referenced in the advisories (swg21970575, swg21971342, swg21971376, swg21971758, swg21972799) as the first action.
  • Where patching is delayed, restrict network access to serialized-object endpoints and management interfaces to trusted hosts only.
  • Upgrade or remove vulnerable Apache Commons Collections versions and apply Java deserialization filters (e.g., JEP 290-style allowlists) where supported.
  • Monitor and alert on deserialization-related exceptions and unexpected child processes spawned by Java application servers.

Detection

  • Inspect Java application server logs for deserialization exceptions and InvokerTransformer or Commons Collections gadget class references.
  • Alert on unexpected process creation (cmd.exe, /bin/sh, powershell) with a Java parent process on affected hosts.
  • Monitor network traffic to serialized-object endpoints for anomalous or oversized serialized payloads.
  • Hunt for outbound connections from affected IBM servers to unusual destinations following deserialization activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-7450 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.". Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0732Ibm tivoli integrated portal vulnerabilityMultiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim…EPSS 1.6%9.8CVE-2023-50316Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send speciall…EPSS 0.35%9.8CVE-2022-22338Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 0.68%9.8CVE-2021-39085Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…EPSS 0.92%9.8CVE-2021-29798Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.8CVE-2021-29903Ibm sterling b2b integrator sql injection vulnerabilityIBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…EPSS 1.1%9.3CVE-2012-5937Ibm gentran integration suite vulnerabilityUnspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, …EPSS 2.6%8.8CVE-2023-38739Ibm sterling b2b integrator cross-site request forgery vulnerabilityIBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an atta…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2015-7450), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.