Arbitrary code execution in Oracle products - CVE-2015-3253

 

Arbitrary code execution in Oracle products - CVE-2015-3253

Published: October 11, 2016 / Updated: January 5, 2017


Vulnerability identifier: #VU831
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3253
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause arbitrary code execution on the target system.
The weakness exists due to improper serialization of runtime/MethodClosure.java. By sending a specially crafted serialized objects attackers can trigger arbitrary code to be executed.
Successful explotation of the vulmerability results in arbitrary code execution or denial of service on the vulnerable system.

Affected software

Oracle Big Data Discovery
Oracle Health Sciences Clinical Development Center
Oracle Retail Order Broker
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Customer Insights
Oracle Retail Merchandising Insights
Oracle Agile PLM Framework
Oracle Commerce Platform
IBM Cloud Pak System
Oracle Communications Converged Application Server
Fedora
groovy18
groovy
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2015-3253

Update to version 2.4.5 or later.

IBM Cloud Pak System - update to 2.3.3.6
groovy18 - addressed in versions 1.8.9-30.fc25, 1.8.9-30.fc26
groovy - addressed in versions 2.4.0-2.fc22, 2.4.4-1.fc23
IBM Spectrum Control - update to 5.4.10
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20

External References

Related Security Bulletins