CVE-2015-6420

SOURCE - github

Summary

Serialized-object interfaces in Java applications using the Apache Commons Collections (ACC) library may allow remote attackers to execute arbitrary commands via a crafted serialized Java object.

EPSS Score: 0.0088 (0.826)

Common Weakness Enumeration (CWE)

SOURCE - nist

Deserialization of Untrusted Data

SOURCE - github

Deserialization of Untrusted Data

SOURCE - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Deserialization of Untrusted Data

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities


NIST

CREATED


UPDATED



EXPLOITABILITY SCORE

10


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high

GitHub

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

N/Ahigh

GitLab

CREATED


UPDATED


SOURCE ID

CVE-2015-6420


EXPLOITABILITY SCORE

10.0


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high