← Vulnerability feed

Vulnerability record · CVE-2015-7501 · published 9 November 2017

CVE-2015-7501: Red Hat JBoss Java deserialization allows remote command execution

Redhat · Data Grid

Multiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to execute arbitrary commands. The flaw affects a wide range of JBoss middleware and platform components, so any exposed service that accepts serialized Java data is at risk.

9.8 CVSS 3.0 Critical EPSS 86% · top 0.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.0 base score, v2 10.0
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
15Affected product versions listed by NVD
56References
17 Jun 2026Last modified by NVD

Description

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required and an EPSS score above the 99th percentile make this a top-priority exposure despite the absence of KEV listing.

What it is

Multiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to execute arbitrary commands. The flaw affects a wide range of JBoss middleware and platform components, so any exposed service that accepts serialized Java data is at risk.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the affected server, leading to full compromise of the host and any data or credentials it holds.

Attack surface

Reached over the network via crafted serialized Java objects sent to a vulnerable JBoss endpoint; the CVSS vector shows no privileges or user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.85562 (99.7th percentile), indicating very high predicted exploitation activity; references are vendor advisories and VDB entries with no exploit tags.

What to do

  • Apply the Red Hat errata (RHSA-2015-2500 through RHSA-2016-1773) for each affected product.
  • Upgrade or remove the vulnerable Apache Commons Collections library where the product permits.
  • Restrict network access to JBoss management, messaging and remoting ports to trusted hosts only.
  • Enable Java deserialization filtering or a serialization whitelist on any service that accepts serialized objects.
  • Monitor vendor advisories for Oracle products that bundle the affected JBoss components.

Detection

  • Alert on serialized Java object streams (hex AC ED 00 05) arriving at JBoss endpoints from unexpected sources.
  • Monitor for child processes spawned by the JBoss Java process, especially shell or command interpreters.
  • Watch for outbound connections from JBoss hosts to unusual destinations following inbound serialized payloads.
  • Review JBoss application and access logs for anomalous deserialization requests or repeated connection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2015-2500.html
http://rhn.redhat.com/errata/RHSA-2015-2501.html
http://rhn.redhat.com/errata/RHSA-2015-2502.html
http://rhn.redhat.com/errata/RHSA-2015-2514.html
http://rhn.redhat.com/errata/RHSA-2015-2516.html
http://rhn.redhat.com/errata/RHSA-2015-2517.html
http://rhn.redhat.com/errata/RHSA-2015-2521.html
http://rhn.redhat.com/errata/RHSA-2015-2522.html
http://rhn.redhat.com/errata/RHSA-2015-2524.html
http://rhn.redhat.com/errata/RHSA-2015-2670.html
http://rhn.redhat.com/errata/RHSA-2015-2671.html
http://rhn.redhat.com/errata/RHSA-2016-0040.html
http://rhn.redhat.com/errata/RHSA-2016-1773.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/78215 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1034097 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037052 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037053 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037640 Third Party AdvisoryVDB Entry
https://access.redhat.com/security/vulnerabilities/2059393 Vendor Advisory
https://access.redhat.com/solutions/2045023 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1279330 Issue TrackingThird Party AdvisoryVDB EntryVendor Advisory
https://rhn.redhat.com/errata/RHSA-2015-2536.html
https://security.netapp.com/advisory/ntap-20240216-0010/
https://www.oracle.com/security-alerts/cpujul2020.html
http://rhn.redhat.com/errata/RHSA-2015-2500.html
http://rhn.redhat.com/errata/RHSA-2015-2501.html
http://rhn.redhat.com/errata/RHSA-2015-2502.html
http://rhn.redhat.com/errata/RHSA-2015-2514.html
http://rhn.redhat.com/errata/RHSA-2015-2516.html
http://rhn.redhat.com/errata/RHSA-2015-2517.html
http://rhn.redhat.com/errata/RHSA-2015-2521.html
http://rhn.redhat.com/errata/RHSA-2015-2522.html
http://rhn.redhat.com/errata/RHSA-2015-2524.html
http://rhn.redhat.com/errata/RHSA-2015-2670.html
http://rhn.redhat.com/errata/RHSA-2015-2671.html
http://rhn.redhat.com/errata/RHSA-2016-0040.html

Track CVE-2015-7501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12149JBoss HTTP Invoker deserialization allows remote code executionThe ReadOnlyAccessFilter doFilter method in the JBoss HTTP Invoker deserializes untrusted data without restricting which classes can be loaded. An un…KEVEPSS 91%analysed8.8CVE-2010-1871JBoss Seam 2 EL injection allows remote code executionJBoss Seam 2, as shipped in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, fails to sanitize input used in JBoss Expression Language …KEVEPSS 83%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2010-1428JBoss EAP Web Console access control bypass via non-GET/POST methodsThe Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses th…KEVEPSS 62%analysed5.3CVE-2010-0738JBoss JMX-Console access control bypass via non-GET/POST HTTP methodsThe JMX-Console web application in Red Hat JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 enforces access control only for GET and POST re…KEVEPSS 79%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2021-31917Infinispan-server-rest improper authentication vulnerabilityA flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2015-7501), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.