Lucene search

K
redhatRedHatRHSA-2015:2501
HistoryNov 20, 2015 - 6:21 p.m.

(RHSA-2015:2501) Critical: Red Hat JBoss Enterprise Application Platform security update

2015-11-2018:21:01
access.redhat.com
18

0.018 Low

EPSS

Percentile

88.4%

Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
applications based on JBoss Application Server 7.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of Red Hat JBoss Enterprise Application Platform 6.1, 6.2, 6.3,
and 6.4 are advised to upgrade to these updated packages.

The JBoss server process must be restarted for the update to take effect.