IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM — WebSphere Application Server and Server Hypervisor Edition
- Added to KEV catalog
- 10 January 2022
- Federal remediation due date
- 10 July 2022
- Weakness classification (CWE)
- CWE-94
CISA Description
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2015-7450
More IBM Vulnerabilities
IBM Langflow Code Injection Vulnerability
IBM Aspera Faspex Code Execution Vulnerability
IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM Data Risk Manager Directory Traversal Vulnerability
IBM Data Risk Manager Remote Code Execution Vulnerability
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services