Lucene search

K
redhatRedHatRHSA-2015:2514
HistoryNov 24, 2015 - 6:01 p.m.

(RHSA-2015:2514) Critical: Red Hat JBoss Enterprise Application Platform security update

2015-11-2418:01:11
access.redhat.com
17

0.018 Low

EPSS

Percentile

88.4%

Red Hat JBoss Enterprise Application Platform is a platform for Java
applications based on JBoss Application Server.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of Red Hat JBoss Enterprise Application Platform 5.2, 5.1.2, and
4.3.10 are advised to upgrade to these updated packages. The JBoss server
process must be restarted for the update to take effect.