← Back to browse · API

CVE-2015-7450

Severity
CRITICAL
CVSS
9.8
EPSS
0.97655
Risk score
59.18
CISA KEV
Yes
PoC
No
Published
2016-01-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2015-7374, GHSA-8987-QGC7-79P9
Products
IBM:WebSphere Application Server and Server Hypervisor Edition, n/a:n/a n/a
Sources
cisa.gov CVE-2015-7450
euvd EUVD-2015-7374

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

References