Arbitrary code execution in Oracle products - CVE-2015-3253
Published: October 11, 2016 / Updated: January 5, 2017
Vulnerability identifier: #VU831
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3253
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated user to cause arbitrary code execution on the target system.
The weakness exists due to improper serialization of runtime/MethodClosure.java. By sending a specially crafted serialized objects attackers can trigger arbitrary code to be executed.
Successful explotation of the vulmerability results in arbitrary code execution or denial of service on the vulnerable system.
The weakness exists due to improper serialization of runtime/MethodClosure.java. By sending a specially crafted serialized objects attackers can trigger arbitrary code to be executed.
Successful explotation of the vulmerability results in arbitrary code execution or denial of service on the vulnerable system.
Affected software
Oracle Big Data Discovery
Oracle Health Sciences Clinical Development Center
Oracle Retail Order Broker
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Customer Insights
Oracle Retail Merchandising Insights
Oracle Agile PLM Framework
Oracle Commerce Platform
IBM Cloud Pak System
Oracle Communications Converged Application Server
Fedora
groovy18
groovy
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
Oracle Health Sciences Clinical Development Center
Oracle Retail Order Broker
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Customer Insights
Oracle Retail Merchandising Insights
Oracle Agile PLM Framework
Oracle Commerce Platform
IBM Cloud Pak System
Oracle Communications Converged Application Server
Fedora
groovy18
groovy
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
How to mitigate CVE-2015-3253
Update to version 2.4.5 or later.
IBM Cloud Pak System - update to 2.3.3.6
groovy18 - addressed in versions 1.8.9-30.fc25, 1.8.9-30.fc26
groovy - addressed in versions 2.4.0-2.fc22, 2.4.4-1.fc23
IBM Spectrum Control - update to 5.4.10
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
groovy18 - addressed in versions 1.8.9-30.fc25, 1.8.9-30.fc26
groovy - addressed in versions 2.4.0-2.fc22, 2.4.4-1.fc23
IBM Spectrum Control - update to 5.4.10
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
External References
Related Security Bulletins
- Arbitrary code execution in Oracle Communications Converged Application Server - Service Controller
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in APM JBoss and APM WebLogic Agent
- Fedora 23 update for groovy
- Fedora 22 update for groovy
- Fedora 26 update for groovy18
- Fedora 25 update for groovy18