Executive brief
IBM WebSphere Application Server and other products are vulnerable to remote code execution via deserialization of untrusted data. The issue stems from the InvokerTransformer class in the Apache Commons Collections library, which allows remote attackers to execute arbitrary commands using crafted serialized Java objects.
Affected products
- IBM WebSphere Application Server
- IBM WebSphere Application Server Hypervisor Edition
- Apache Commons Collections
- IBM Tivoli Common Reporting 2.1, 2.1.1, 2.1.1.2, 3.1, 3.1.0.1, 3.1.0.2, 3.1.2, 3.1.2.1
- IBM Sterling B2B Integrator 5.2
- IBM Sterling Integrator 5.1
- IBM Watson Content Analytics 3.0 through 3.0.0.6, 3.5 through 3.5.0.3
- IBM Watson Explorer Analytical Components 10.0 through 10.0.0.2, 11.0
Timeline
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-10: disclosed