Red Hat issued Critical updates for CVE-2015-7501, an Apache Commons Collections unsafe Java deserialization flaw that can let a remote attacker execute arbitrary code under the privileges of an affected application. Exploitation requires an exposed endpoint that accepts and blindly deserializes untrusted serialized data while vulnerable Commons Collections classes are on the application classpath; unauthenticated access to JMXInvokerServlet can satisfy these conditions in affected deployments.
Affected offerings include JBoss SOA Platform 5.3.1, JBoss Data Grid 6.4.1 and 6.5.1, JBoss Data Virtualization 6.0.0–6.2.0, JBoss EAP 5.2, JBoss Operations Network 3.3.4, and JBoss BPM Suite 6.1.0. Organizations should apply the relevant Red Hat security updates, back up installations, and stop and restart JBoss services as required; applications that ship their own Commons Collections JARs may remain vulnerable and require separate remediation or removal of the vulnerable classes after testing.

See real exploitation activity before you spend the cycle.
43 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2020:4274 for rh-maven35-apache-commons-collections4 in Red Hat Software Collections, providing version 4.0-7.3.el7 to remediate CVE-2015-7501. The flaw in Apache Commons Collections InvokerTransformer could permit code execution through unsafe deserialization.
Red Hat issued Critical advisory RHSA-2016:0118 for JBoss Operations Network 3.3.5, replacing version 3.3.4. The update remediated the unsafe-deserialization remote-code-execution flaws CVE-2015-7501 in Apache Commons Collections and CVE-2015-3253 in Groovy.
Red Hat issued Critical advisory RHSA-2016:0040, providing Hotfix 11 for JBoss Operations Network 3.1.2 to remediate the Apache Commons Collections deserialization RCE vulnerability CVE-2015-7501. The update includes fixes for server, agent, and core GUI components, and Red Hat advised users to back up installations before applying it.
Red Hat issued Important advisory RHSA-2015:2671 for jakarta-commons-collections on Red Hat Enterprise Linux 5, updating the package to block deserialization of unsafe classes associated with CVE-2015-7501. Red Hat advised affected users to upgrade and restart applications using the library.
Red Hat issued Critical advisory RHSA-2015:2670 for Red Hat JBoss BRMS 5.3.1, updating Apache Commons Collections to remediate CVE-2015-7501. The unsafe deserialization flaw could allow a remote attacker to execute arbitrary code with the affected application's permissions.
Red Hat issued Critical advisory RHSA-2015:2579 for JBoss BPM Suite 6.1.0, remediating the Apache Commons Collections deserialization vulnerability that could enable remote code execution.
Red Hat issued Critical advisory RHSA-2015:2578 for JBoss BRMS 6.1.0, updating Apache Commons Collections to remediate CVE-2015-7501. The unsafe deserialization flaw could allow a remote attacker to execute arbitrary code with the permissions of an application using the vulnerable library.
Red Hat issued Critical advisory RHSA-2015:2540, updating JBoss EAP 6.4 from 6.4.4 to 6.4.5 for RHEL 7. The update remediated CVE-2015-7501 and CVE-2015-5304; Red Hat instructed administrators to restart the JBoss server after installation.
Red Hat issued Critical advisory RHSA-2015:2539, updating JBoss EAP 6.4 from 6.4.4 to 6.4.5 for RHEL 6. The update remediated the Commons Collections deserialization RCE flaw CVE-2015-7501 and the EAP shutdown authorization flaw CVE-2015-5304.
Red Hat issued Critical advisory RHSA-2015:2538 for JBoss EAP 6.4 on RHEL 5, updating EAP from 6.4.4 to 6.4.5. The update remediates CVE-2015-7501 and CVE-2015-5304, an authorization flaw allowing certain non-administrator roles to shut down an EAP server.
Red Hat issued Critical advisory RHSA-2015:2536 for JBoss EAP 6.3, updating apache-commons-collections-eap6 to remediate CVE-2015-7501 on RHEL 5, 6, and 7. The deserialization flaw could permit remote code execution with the affected application's permissions; Red Hat required a JBoss server restart after updating.
Red Hat published Critical advisory RHSA-2015:2535, updating Apache Commons Collections packages for JBoss Enterprise Application Platform 5.2 on supported Red Hat Enterprise Linux releases.
Red Hat issued Critical advisory RHSA-2015:2537 for Red Hat JBoss Portal 6.2.0, providing an updated Apache Commons Collections package to remediate CVE-2015-7501. Red Hat advised customers to install the patch and back up deployed applications, databases, settings, and customized configuration files before updating.
Red Hat published Critical advisory RHSA-2015:2534, providing a security update for JBoss Data Virtualization 6.0.0, 6.1.0, and 6.2.0 to remediate CVE-2015-7501.
Red Hat issued Important advisory RHSA-2015:2523 for rh-java-common-apache-commons-collections in Red Hat Software Collections 2, addressing CVE-2015-7501 by blocking deserialization of unsafe classes. Red Hat advised affected users to upgrade and restart applications using Commons Collections.
Red Hat issued Important advisory RHSA-2015:2522 for Red Hat Enterprise Linux 7, releasing apache-commons-collections-3.2.1-22.el7_2 to block unsafe deserialization classes associated with CVE-2015-7501. Red Hat advised users to update affected packages and restart applications using the library.
Red Hat issued Important advisory RHSA-2015:2521 for Red Hat Enterprise Linux 6, releasing jakarta-commons-collections 3.2.1-3.5.el6_7 to block unsafe deserialization classes associated with CVE-2015-7501. Red Hat advised customers to install the update and restart applications using the library.
Red Hat issued Critical advisory RHSA-2015:2517 for JBoss Fuse Service Works 6.0.0, updating Apache Commons Collections to remediate CVE-2015-7501. The unsafe deserialization flaw could allow a remote attacker to execute arbitrary code with the privileges of the affected application.
Red Hat issued Critical advisory RHSA-2015:2516 for JBoss SOA Platform 5.3.1, releasing an update for the Apache Commons Collections deserialization flaw that could allow remote code execution.
Red Hat issued Critical advisory RHSA-2015:2514 for JBoss EAP 5.2, 5.1.2, and 4.3.10, updating Apache Commons Collections to remediate CVE-2015-7501. The deserialization flaw could allow remote code execution with the affected application's permissions; Red Hat advised upgrading and restarting JBoss servers.
Red Hat issued Critical advisory RHSA-2015:2502 for JBoss Data Grid 6.4.1 and 6.5.1, providing updated Apache Commons Collections packages to remediate the unsafe deserialization remote-code-execution flaw.
Red Hat closed Bugzilla 1275301 with an ERRATA resolution, stating that RHSA-2015:2541 was expected to resolve the RHEL 7 picketbox upgrade issue and provide updated files. Users for whom the advisory did not resolve the issue were instructed to open a new bug report.
Red Hat closed Bugzilla 1275289 with an ERRATA resolution, stating that RHSA-2015:2541 provides updated files and remediation information for the RHEL 7 hibernate4-eap6 upgrade issue. Users for whom the advisory did not resolve the issue were instructed to file a new bug report.
Red Hat closed Bugzilla 1275308 with resolution ERRATA, stating that RHSA-2015:2541 should resolve the RHEL 7 ironjacamar-eap6 upgrade issue and provide updated files. Users for whom the advisory did not resolve the issue were instructed to open a new bug report.
Red Hat closed Bugzilla 1275684 with resolution ERRATA and directed users to RHSA-2015:2541 for updated files and remediation information for the RHEL 7 jboss-hal issue.
Red Hat released Critical server patch RHSA-2015:2547 for JBoss Operations Network 3.2.3, replacing vulnerable Apache Commons Collections 3.2.1 files to remediate CVE-2015-7501. Administrators were advised to stop each server before patching and apply the patch separately to every server in high-availability deployments.
Red Hat released JBoss Fuse 6.2.1, an Important-security-impact micro release updating JBoss Fuse 6.2.0. It fixes CVE-2015-7501, CVE-2015-3253, and CVE-2015-5181, and Red Hat advised all JBoss Fuse 6.2.0 users to apply the update.
Red Hat released Critical updated jboss-ec2-eap packages for JBoss EAP 6.4.4 on RHEL 6, fixing CVE-2015-7501 and the EAP shutdown authorization flaw CVE-2015-5304. The packages add compatibility with EAP 6.4.5; Red Hat advised users to upgrade and restart the EAP server.
Red Hat released Critical JBoss BRMS 6.2.0 through the Customer Portal, replacing version 6.1.2. The update fixes CVE-2015-7501, CVE-2015-0250, and CVE-2015-6748; Red Hat advised users to back up installations, stop the JBoss Application Server for installation, and restart it afterward.
Red Hat released Critical JBoss BPM Suite 6.2.0 through the Customer Portal, replacing version 6.1.2. The update fixes CVE-2015-7501, CVE-2015-0250, and CVE-2015-6748, and Red Hat advised affected users to upgrade.
Red Hat made a Critical server patch available for JBoss Operations Network 3.3 Update 4, replacing vulnerable Apache Commons Collections JARs to address CVE-2015-7501.
Red Hat released JBoss A-MQ 6.2.1, an Important-security-impact micro release for JBoss A-MQ 6.2.0. The update fixes CVE-2015-7501, Groovy deserialization flaw CVE-2015-3253, and stored XSS flaw CVE-2015-5181 in the A-MQ console.
Red Hat closed Bugzilla 1275315 with resolution ERRATA, stating that RHSA-2015:2539 provides the updated files needed to resolve the RHEL 6 jbossweb upgrade issue. Users for whom the advisory did not resolve the problem were instructed to file a new bug report.
Red Hat closed Bugzilla 1275329 with an ERRATA resolution, directing users to RHSA-2015:2539 for updated files. The fix upgraded jboss-as-console to build 2.5.11-1.Final_redhat_1.1.ep6.el6.
Red Hat closed Bugzilla 1275318 with resolution ERRATA, stating that RHSA-2015:2539 should resolve the RHEL 6 jboss-xnio-base issue and provide updated files. Users for whom the update did not resolve the issue were instructed to open a new bug report.
Red Hat closed Bugzilla 1275299 with an ERRATA resolution, stating that RHSA-2015:2539 should resolve the RHEL 6 picketbox upgrade issue and provide updated files. Users for whom the advisory did not resolve the problem were instructed to file a new bug report.
Red Hat closed Bugzilla 1279593 with resolution ERRATA, stating that updated hornetq files provided through RHSA-2015:2538 should resolve the RHEL 5 issue. Users for whom the advisory did not resolve the problem were instructed to file a new bug report.
Red Hat closed Bugzilla 1275683 with resolution ERRATA, stating that RHSA-2015:2538 should resolve the RHEL 5 jboss-hal issue and provide updated files. Users for whom the advisory did not resolve the issue were instructed to file a new bug report.
Red Hat closed Bugzilla 1275690 with resolution ERRATA, stating that a required upgrade of jboss-security-negotiation should resolve the reported RHEL 5 issue. Users were directed to RHSA-2015:2538 for updated files.
Red Hat closed Bugzilla 1275288 with an ERRATA resolution, stating that RHSA-2015:2538 should resolve the RHEL 5 hibernate4-eap6 issue and provide updated files. Users for whom the advisory did not resolve the issue were instructed to open a new bug report.
Red Hat closed Bugzilla 1275330 with resolution ERRATA, stating that RHSA-2015:2538 should resolve the RHEL 5 jboss-as-console issue and provide updated files. Users for whom the advisory did not resolve the issue were instructed to open a new bug report.
Red Hat issued RHSA-2015:2500 and RHSA-2015:2501 to remediate CVE-2015-7501 in affected JBoss Enterprise Application Platform releases, including 5.1.2, 4.3.10, 6.3.z, and 6.4.z.
Red Hat identified CVE-2015-7501 as an Apache Commons Collections deserialization vulnerability affecting listed JBoss Middleware products, potentially allowing unauthenticated remote code execution through JMXInvokerServlet when untrusted serialized input is deserialized. It advised temporarily removing InvokerTransformer, InstantiateFactory, and InstantiateTransformer from Commons Collections JARs after testing, and warned that applications bundling their own library require separate remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.