Apache Commons Collections contained a critical unsafe-deserialization vulnerability, CVE-2015-7501, in its serializable InvokerTransformer component. An attacker able to supply crafted serialized Java objects to exposed endpoints—including JMX, RMI, or remote EJB services—could chain vulnerable classes with sun.reflect.annotation.AnnotationInvocationHandler to execute arbitrary code under the permissions of the affected Java application. The flaw affected Commons Collections 3.0 and 4.0 and exposed products and applications using the library, including WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS.
Apache addressed the issue in Commons Collections versions 3.2.2 and 4.1 by preventing InvokerTransformer transformations following deserialization. Red Hat also issued a critical update for JBoss Operations Network 3.3.4, directing customers to shut down and patch every server individually, including each node in high-availability deployments. Organizations should identify applications that deserialize untrusted Java objects and either upgrade the library or apply vendor-provided patches.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued a critical security update for JBoss Operations Network 3.3 Update 4 to remediate CVE-2015-7501, which could allow remote code execution during deserialization through a specially constructed class chain. The patch replaced vulnerable commons-collections library files for affected JBoss ON 3.3.4 deployments.
Apache Commons Collections addressed an unsafe deserialization flaw in serializable InvokerTransformer that could be combined with AnnotationInvocationHandler to execute arbitrary Java code through exposed serialized-object endpoints. Fixes were released in Commons Collections 3.2.2 and 4.1.
Foxglove Security published research on a vulnerability affecting Java applications and products including WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
commons.apache.org
Open sourceaccess.redhat.com
Open sourceblogs.apache.org
Open sourceissues.apache.org
Open sourcefoxglovesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.