CVE-2015-7450: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-01-10. EPSS: 97.8% chance of exploitation in the next 30 days.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Affected products
- IBM Sterling b2b Integrator: version 5.2 only
- IBM Sterling Integrator: version 5.1 only
- IBM Tivoli Common Reporting: version 2.1 only; version 2.1.1 only; version 2.1.1.2 only; version 3.1 only; version 3.1.0.1 only; version 3.1.0.2 only; …
- IBM Watson Content Analytics: from 3.0, up to and including 3.0.0.6; from 3.5, up to and including 3.5.0.3
- IBM Watson Explorer Analytical Components: from 10.0, up to and including 10.0.0.2; version 11.0 only
- IBM Watson Explorer Annotation Administration Console: from 10.0, up to and including 10.0.0.2; version 11.0 only
- IBM WebSphere Application Server: version 7.0.0.0 only; version 8.0.0.0 only; version 8.5 only; version 8.5.0.0 only; version 8.5.5.5 only
Published 2016-01-02. Last modified 2026-06-17.