CVE-2015-6420: Apache Commons Collections
Critical severity, CVSS 9.8. EPSS: 18.8% chance of exploitation in the next 30 days.
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Affected products
- Apache Commons Collections: from 3.0, before 3.2.2 (fixed in 3.2.2); version 4.0 only
Published 2015-12-15. Last modified 2026-10-07.