SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   IBM SPSS Vendors:   IBM
(IBM Issues Fix for IBM SPSS Analytic Server) Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System
SecurityTracker Alert ID:  1034359
SecurityTracker URL:  http://securitytracker.com/id/1034359
CVE Reference:   CVE-2015-7450   (Links to External Site)
Date:  Dec 9 2015
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): Analytic Server 2.0
Description:   A vulnerability was reported in Apache Commons Components. A remote user can execute arbitrary code on the target system. IBM SPSS Analytic Server is affected.

A remote user can send specially crafted data to an application or application server that uses or includes the Java 'InvokerTransformer.class' to deserialize data to execute arbitrary code on the target system.

Applications that deserialize untrusted Java objects may be affected.

Applications that use other libraries (e.g., Groovy, Spring) may also be affected.

Application servers (e.g., WebLogic, WebSphere, JBoss) may be affected.

Steve Breen of Foxglove reported details of this vulnerability.

The advisory is available at:

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#commons

Christopher Frohoff and Gabriel Lawrence originally reported this vulnerability [at AppSecCali 2015 in January 2015].

The original advisory is available at:

http://www.slideshare.net/frohoff1/appseccali-2015-marshalling-pickles

Impact:   A remote user can execute arbitrary code on the target system.
Solution:   IBM has issued a fix for IBM SPSS Analytic Server (2.0.0.1 Interim Fix).

The IBM advisory is available at:

https://www-304.ibm.com/support/docview.wss?uid=swg21971725

Vendor URL:  www-304.ibm.com/support/docview.wss?uid=swg21971725 (Links to External Site)
Cause:   Access control error
Underlying OS:  Linux (Any)

Message History:   This archive entry is a follow-up to the message listed below.
Nov 9 2015 Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC