Lucene search

K
redhatRedHatRHSA-2015:2500
HistoryNov 20, 2015 - 12:00 a.m.

(RHSA-2015:2500) Critical: Red Hat JBoss Enterprise Application Platform 6.4 security update

2015-11-2000:00:00
access.redhat.com
33

0.018 Low

EPSS

Percentile

88.4%

Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
applications based on JBoss Application Server 7.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of Red Hat JBoss Enterprise Application Platform 6.4 on Red Hat
Enterprise Linux 5, 6, and 7 are advised to upgrade to these updated
packages. The JBoss server process must be restarted for the update to
take effect.