CVE

Id
84727  
CVE No.
CVE-2015-7450  
Status
Candidate  
Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.  
Phase
Assigned (20150929)  
Votes
None (candidate not yet proposed)  
Comments