ZeroHour

CVE-2015-7450

KEVlarge

Deserialization RCE in IBM WebSphere Application Server and Hypervisor Edition

CISA: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

CVSS
EPSS
98%p100
Published
KEV added
AI analysis

CVE-2015-7450 is a remote code execution flaw in IBM WebSphere Application Server and WebSphere Application Server Hypervisor Edition, where interfaces that accept serialized Java objects fail to adequately validate them, allowing code injection (CWE-94). A remote attacker who can send a crafted serialized object to a vulnerable serialized-object interface causes the application server to deserialize it and execute arbitrary commands on the host with the server's privileges. Organizations running the affected IBM products, particularly internet-exposed or business-critical WebSphere deployments, are affected. The flaw is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 with a required action to apply vendor updates, and EPSS assigns a 97.7% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, CVSS has not yet been scored, and ransomware use is not confirmed.

What to do: Apply IBM's WebSphere Application Server updates per vendor instructions, as CISA's KEV entry requires, and ensure Hypervisor Edition appliances are updated as well. Until patched, restrict internet access to WebSphere application and administrative serialized-object endpoints with firewalls and monitor for signs of exploitation. Given the 97.7% EPSS and KEV listing, prioritize internet-facing and business-critical WAS instances first.

Affected
IBM WebSphere Application Server
IBM WebSphere Application Server Server Hypervisor Edition
Estimated exposure
large≈tens of thousands of internet-exposed WebSphere instances; likely 100k+ total enterprise deployments (est.) — Public internet-wide scans have long indexed tens of thousands of IBM WebSphere hosts, and WebSphere's role as a mainstream enterprise Java application server implies a substantially larger installed base behind firewalls.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

CISA Known Exploited Vulnerability
Affected
IBM WebSphere Application Server and Server Hypervisor Edition
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
IBM
Products
WebSphere Application Server and Server Hypervisor Edition
Weakness
CWE-94

In the news