SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   Oracle Financial Services Applications Vendors:   Oracle
(Oracle Issues Fix for Oracle Financial Services Applications) Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System
SecurityTracker Alert ID:  1036385
SecurityTracker URL:  http://securitytracker.com/id/1036385
CVE Reference:   CVE-2015-7501   (Links to External Site)
Date:  Jul 20 2016
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  

Description:   A vulnerability was reported in Apache Commons Components. A remote user can execute arbitrary code on the target system. Oracle Financial Services Applications is affected.

A remote user can send specially crafted data to an application or application server that uses or includes the Java 'InvokerTransformer.class' to deserialize data to execute arbitrary code on the target system.

Applications that deserialize untrusted Java objects may be affected.

Applications that use other libraries (e.g., Groovy, Spring) may also be affected.

Application servers (e.g., WebLogic, WebSphere, JBoss) may be affected.

Steve Breen of Foxglove reported details of this vulnerability.

The advisory is available at:

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#commons

Christopher Frohoff and Gabriel Lawrence originally reported this vulnerability [at AppSecCali 2015 in January 2015].

The original advisory is available at:

http://www.slideshare.net/frohoff1/appseccali-2015-marshalling-pickles

Impact:   A remote user can execute arbitrary code on the target system.
Solution:   Oracle has issued a fix for CVE-2015-7501 for Oracle Financial Services Applications.

The Oracle advisory is available at:

http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Vendor URL:  www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html (Links to External Site)
Cause:   Access control error

Message History:   This archive entry is a follow-up to the message listed below.
Nov 9 2015 Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC