CVE-2015-6420
Insecure Deserialization in Apache Commons Collection
Description
Serialized-object interfaces in Java applications using the Apache Commons Collections (ACC) library may allow remote attackers to execute arbitrary commands via a crafted serialized Java object.
Base CVSS
7.8
EPSS Score
13.77%
Introduced Version
0,3.0,3.1,3.0-dev2,20040102.233541,20040616,4.01,4.0,4.01_1,3.2.1_1
Fix Available
4.1,3.2.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed