CISA KEV · catalog date Jan 10, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute…
Exploited in the wild (CISA KEV since Jan 10, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 97.7% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
- State
- PUBLISHED
- Published
- Jan 2, 2016
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAibmOriginal evidence ↗
Record text: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Inspect raw assertion
- Field
container- Value
- Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Inspect raw assertion
- Field
observed_exploitation- Value
- IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 97.66% probability · 99.9th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.976550000000; percentile 0.998980000000
FIRST EPSS · score date Aug 26, 2026 · 99.9th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Inspect raw assertion
- Field
container- Value
- Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Inspect raw assertion
- Field
observed_exploitation- Value
- IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
97.66% probability · 99.9th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.976550000000; percentile 0.998980000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
8 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-75ca49e501fe1c58a8c9d05fd73bba3001e0d5731b1ebf11ccae6e63bd48e3f3Linked exactInspect raw assertion
cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f805ba3a-178d-416e-9ded-4258f71a17c8
product-543af35bfd93bc378d3dcd961e9e4f8fe6e77092fcd597a20c388218e5f9e187Linked exactInspect raw assertion
cpe:2.3:a:ibm:sterling_integrator:5.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8597a678-3633-4f5d-95a9-5aab168f92b7
product-44e6d735350bee32b124ece350c0f681d3f423b603af58ae217511a4f88483d5Linked exactInspect raw assertions
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5d680d54-ee53-4658-98e1-64f316d23177
cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
393ab012-4f9c-4893-827e-4480aec16de5
cpe:2.3:a:ibm:tivoli_common_reporting:2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f56c076e-a4fb-432f-a7cb-0c37cdec94c0
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1938833-b19e-4df2-8e2c-e2ade876d44b
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bed14b09-f9ff-4db4-9404-0d3a2bac7fdd
cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a792593c-b2d4-425d-9ec4-3581a77474b5
cpe:2.3:a:ibm:tivoli_common_reporting:3.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a1b8dfb-2004-4449-a4a7-802662d571eb
cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2dbe91df-8844-4adb-ac02-839305f82b0f
product-0a0ffa024916255ea2eea5ade60a2235c155558d98a4623b449797a43aa0a00bLinked exactInspect raw assertions
cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 3.0; through including 3.0.0.6
- Match ID
18d82ca9-8afe-44ff-956c-f2b8e42b3eb4
cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- from including 3.5; through including 3.5.0.3
- Match ID
b22f02c8-bf16-4202-82b7-e167e0f6fc75
product-582ecc9e4083d5944249df45b65eb355b410af61457e67bf389922aa4355cde6Linked exactInspect raw assertions
cpe:2.3:a:ibm:watson_explorer_analytical_components:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 10.0; through including 10.0.0.2
- Match ID
58412a55-8780-417e-9e89-af9f5dd19bc4
cpe:2.3:a:ibm:watson_explorer_analytical_components:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8aad3a69-115d-4d6c-b5a9-7590e97b15a9
product-10e3d41dad450b527b38b936e60079a0616fcf05f140e2a89805d31d345e1c4aLinked exactInspect raw assertions
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66634c1b-0e8a-48fd-a0dc-d5ad4cf29ec7
cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 10.0; through including 10.0.0.2
- Match ID
41147b26-c469-48ee-b139-c0d0b07bbded
product-88181675dee34576a91448b82c4fe8c76ccae13ab8f1833e019f71b3a54ffee4Linked exactInspect raw assertions
cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0507670-6059-4164-ad54-a5172de8313f
cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:hypervisor:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ab001073-3fe0-452b-94fb-57b4555f7ce9
cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a207b0aa-df2f-4b1b-9d87-d812e33adbd0
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c43fbac-2dd2-43cb-ac5f-56741bb2a31c
cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3029a691-2288-453a-8fc0-7598ef60357c
Affected-product evidence
Accepted scope and product mapping
7 canonical links · 1 source-reported links
vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-0a0ffa024916255ea2eea5ade60a2235c155558d98a4623b449797a43aa0a00b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9d09a5d9-fc25-4e2a-867a-4eca083e1b47af30f097-1f94-4f96-8eeb-67be18e6dc9bvendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-10e3d41dad450b527b38b936e60079a0616fcf05f140e2a89805d31d345e1c4a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2d3d1b9a-3c16-4298-a980-57f362be96662d8d18f4-e905-4847-bc28-a696f63cd413vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-44e6d735350bee32b124ece350c0f681d3f423b603af58ae217511a4f88483d5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11cdaf8e-cab6-445f-8fb2-d57cdb3353b83d9ea110-e11a-4368-aa7d-aa8efb02c35f4b0ae9a7-8c11-458f-bb7b-bf6b6d6f2d656775d359-8a24-4fb4-b334-d9be9c12e058a997fc00-3c9d-4606-a01b-2c2fb1dbf396d9838d00-65c2-4f02-b0fc-64f4e7dd5b4edaa82601-48f2-448f-b80e-4d763fc6de49e56e5cd7-0532-4cff-9bb1-42e240b8130cvendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-543af35bfd93bc378d3dcd961e9e4f8fe6e77092fcd597a20c388218e5f9e187
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ccf934de-8443-42fe-9522-71f0bf93febdvendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-582ecc9e4083d5944249df45b65eb355b410af61457e67bf389922aa4355cde6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
50cf87bc-78c8-4ad0-859a-303ecfe2467f71ccbd6e-9df5-4b01-bcd6-498bd984b0e8vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-75ca49e501fe1c58a8c9d05fd73bba3001e0d5731b1ebf11ccae6e63bd48e3f3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d9599ad-4c82-43b0-b631-911c0b718e26vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-88181675dee34576a91448b82c4fe8c76ccae13ab8f1833e019f71b3a54ffee4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d5fc696-c81e-46a2-8a5f-8635bdc571b06b831392-382c-41d9-bd9b-edf0887a8125bb06c779-f026-4b50-8df8-458088d121f1e108bc84-d13e-4374-8677-0e614601bbdaec6e78b7-2f24-408f-b667-6e6085ed84daCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3b4725b3-5846-4a78-a607-45d999678ca0Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.