Vulnerability record · CVE-2015-7501 · published 9 November 2017
CVE-2015-7501: Red Hat JBoss Java deserialization allows remote command execution
Redhat · Data Grid
Multiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to execute arbitrary commands. The flaw affects a wide range of JBoss middleware and platform components, so any exposed service that accepts serialized Java data is at risk.
Description
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and an EPSS score above the 99th percentile make this a top-priority exposure despite the absence of KEV listing.
What it is
Multiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to execute arbitrary commands. The flaw affects a wide range of JBoss middleware and platform components, so any exposed service that accepts serialized Java data is at risk.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the affected server, leading to full compromise of the host and any data or credentials it holds.
Attack surface
Reached over the network via crafted serialized Java objects sent to a vulnerable JBoss endpoint; the CVSS vector shows no privileges or user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.85562 (99.7th percentile), indicating very high predicted exploitation activity; references are vendor advisories and VDB entries with no exploit tags.
What to do
- Apply the Red Hat errata (RHSA-2015-2500 through RHSA-2016-1773) for each affected product.
- Upgrade or remove the vulnerable Apache Commons Collections library where the product permits.
- Restrict network access to JBoss management, messaging and remoting ports to trusted hosts only.
- Enable Java deserialization filtering or a serialization whitelist on any service that accepts serialized objects.
- Monitor vendor advisories for Oracle products that bundle the affected JBoss components.
Detection
- Alert on serialized Java object streams (hex AC ED 00 05) arriving at JBoss endpoints from unexpected sources.
- Monitor for child processes spawned by the JBoss Java process, especially shell or command interpreters.
- Watch for outbound connections from JBoss hosts to unusual destinations following inbound serialized payloads.
- Review JBoss application and access logs for anomalous deserialization requests or repeated connection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7501 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7501), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.