Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Vulnerability in Java Deserialization Affecting Cisco Products

cisco-sa-20151209-java-deserialization · High · Published · Updated

A vulnerability in the Java deserialization used by the Apache Commons Collections (ACC) library could allow an unauthenticated, remote attacker to execute arbitrary code. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by submitting crafted input to an application on a targeted system that uses the ACC library. After the vulnerable library on the affected system deserializes the content, the attacker could execute arbitrary code on the system, which could be used to conduct further attacks. On November 6, 2015, Foxglove Security Group published information about a remote code execution vulnerability that affects multiple releases of the ACC library. The report contains detailed proof-of-concept code for a number of applications, including WebSphere Application Server, JBoss, Jenkins, OpenNMS, and WebLogic. This is a remotely exploitable vulnerability that allows an attacker to inject any malicious code or execute any commands that exist on the server. A wide range of potential impacts includes allowing the attacker to obtain sensitive information. Object serialization is a technique that many programming languages use to convert an object into a sequence of bits for transfer purposes. Deserialization is a technique that reassembles those bits back to an object. This vulnerability occurs in Java object serialization for network transport and object deserialization on the receiving side. Many applications accept serialized objects from the network without performing input validation checks before deserializing it. Crafted serialized objects can therefore lead to execution of arbitrary attacker code. Although the problem itself is in the serialization and deserialization functionality of the Java programming language, the ACC library is known to be affected by this vulnerability. Any application or application framework could be vulnerable if it uses the ACC library and deserializes arbitrary, user-supplied Java serialized data. Additional details about the vulnerability are available at the following links: Official Vulnerability Note from CERT Foxglove Security Apache Commons Statement Oracle Security Alert Cisco will release software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2015-6420
Cisco Bug IDsCSCux17638, CSCux18412, CSCux21425, CSCux34567, CSCux34572, CSCux34575, CSCux34589, CSCux34591, CSCux34612, CSCux34645, CSCux34647, CSCux34652, CSCux34656, CSCux34664, CSCux34665, CSCux34667, CSCux34668, CSCux34669, CSCux34671, CSCux34672, CSCux34688, CSCux34690, CSCux34692, CSCux34705, CSCux34708, CSCux34715, CSCux34720, CSCux34725, CSCux34742, CSCux34754, CSCux34781, CSCux34792, CSCux34827, CSCux34833, CSCux34835, CSCux34852, CSCux34853, CSCux34859, CSCux34874, CSCux34922, CSCux34942, CSCux34953, CSCux34955, CSCux34974, CSCux34982, CSCux35022, CSCux35044, CSCux35046, CSCux35070, CSCux35084, CSCux35085, CSCux35106, CSCux35135, CSCux35147
CVSS ScoreBase NA
Product Names From Source
Cisco Secure Access Control System (ACS), Cisco Unity, Cisco Prime Access Registrar, Cisco Emergency Responder, Cisco Unity Express, Cisco NAC Appliance Software, Cisco Unified Contact Center Enterprise, Cisco Unified Customer Voice Portal (CVP), Cisco IP Interoperability and Collaboration System (IPICS), Cisco Unity Connection, Cisco TelePresence, Cisco Security Manager, Cisco Unified Communications Manager, Cisco Digital Media Manager Software, Cisco MeetingPlace Server, Cisco WebEx Meeting Center, Cisco Show and Share, Cisco Mobility Services Engine, Cisco Identity Services Engine Software, Cisco ASA CX Context-Aware Security Software, Cisco Prime Security Manager (PRSM), Cisco Prime LAN Management Solution (LMS), Cisco Unified Communications Domain Manager, Cisco Prime Infrastructure, Cisco WebEx Meetings Server, Cisco Prime Central, Cisco SocialMiner, Cisco MediaSense, Cisco Unified SIP Proxy, Cisco UCS Director, Cisco Unified Intelligence Center, Cisco Broadband Access Center Telco Wireless Software, Cisco Prime Service Catalog, Cisco Prime Optical, Cisco Prime Provisioning, Cisco Visual Quality Experience, Cisco Prime License Manager, Cisco Prime Network Services Controller, Cisco Videoscape Conductor, Cisco WebEx Meetings for Android, Cisco WebEx Meetings for Windows Phone 8, Cisco Unified E-Mail Interaction Manager, Cisco Data Center Analytics Framework, Cisco Prime Collaboration Provisioning, Cisco Cloupia Unified Infrastructure Controller, Cisco Prime Performance Manager, Cisco Unified Attendant Console, Cisco Videoscape Control Suite, Cisco Small Business Video Surveillance Cameras Firmware, Cisco Hosted Collaboration Mediation Fulfillment, Cisco Cloud Services Platform 2100, Cisco Prime Home, Cisco Registered Envelope Service, Cisco Broadband Access Center Telco and Wireless, Cisco Cloud Services Platforms, Cisco Prime Home Installation, Unified E-Mail Interaction Manager

Related Products

Product CVE Evidence
Unified E-Mail Interaction Manager CVE-2015-6420 Cisco OpenVuln
Cisco Webex Meetings CVE-2015-6420 Cisco OpenVuln
Cisco WebEx Meetings for Windows Phone 8 CVE-2015-6420 Cisco OpenVuln
Cisco WebEx Meetings for Android CVE-2015-6420 Cisco OpenVuln
Cisco WebEx Meetings Server CVE-2015-6420 Cisco OpenVuln
Cisco WebEx Meeting Center CVE-2015-6420 Cisco OpenVuln
Cisco Visual Quality Experience CVE-2015-6420 Cisco OpenVuln
Cisco Videoscape Control Suite CVE-2015-6420 Cisco OpenVuln
Cisco Videoscape Conductor CVE-2015-6420 Cisco OpenVuln
Cisco Unity Express CVE-2015-6420 Cisco OpenVuln
Cisco Unity Connection CVE-2015-6420 Cisco OpenVuln
Cisco Unity CVE-2015-6420 Cisco OpenVuln
Cisco Unified SIP Proxy CVE-2015-6420 Cisco OpenVuln
Cisco Unified Intelligence Center CVE-2015-6420 Cisco OpenVuln
Cisco Unified E-Mail Interaction Manager CVE-2015-6420 Cisco OpenVuln
Cisco Unified Customer Voice Portal (CVP) CVE-2015-6420 Cisco OpenVuln
Cisco Unified Contact Center Enterprise CVE-2015-6420 Cisco OpenVuln
Cisco Unified Contact Center CVE-2015-6420 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2015-6420 Cisco OpenVuln
Cisco Unified Communications Domain Manager CVE-2015-6420 Cisco OpenVuln
Cisco Unified Attendant Console CVE-2015-6420 Cisco OpenVuln
Cisco UCS Director CVE-2015-6420 Cisco OpenVuln
Cisco TelePresence CVE-2015-6420 Cisco OpenVuln
Cisco SocialMiner CVE-2015-6420 Cisco OpenVuln
Cisco Small Business Video Surveillance Cameras Firmware CVE-2015-6420 Cisco OpenVuln
Cisco Show and Share CVE-2015-6420 Cisco OpenVuln
Cisco Security Manager CVE-2015-6420 Cisco OpenVuln
Cisco Secure Access Control System (ACS) CVE-2015-6420 Cisco OpenVuln
Cisco Registered Envelope Service CVE-2015-6420 Cisco OpenVuln
Cisco Prime Service Catalog CVE-2015-6420 Cisco OpenVuln
Cisco Prime Security Manager (PRSM) CVE-2015-6420 Cisco OpenVuln
Cisco Prime Provisioning CVE-2015-6420 Cisco OpenVuln
Cisco Prime Performance Manager CVE-2015-6420 Cisco OpenVuln
Cisco Prime Optical CVE-2015-6420 Cisco OpenVuln
Cisco Prime Network Services Controller CVE-2015-6420 Cisco OpenVuln
Cisco Prime Network CVE-2015-6420 Cisco OpenVuln
Cisco Prime License Manager CVE-2015-6420 Cisco OpenVuln
Cisco Prime LAN Management Solution (LMS) CVE-2015-6420 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2015-6420 Cisco OpenVuln
Cisco Prime Home Installation CVE-2015-6420 Cisco OpenVuln
Cisco Prime Home CVE-2015-6420 Cisco OpenVuln
Cisco Prime Collaboration Provisioning CVE-2015-6420 Cisco OpenVuln
Cisco Prime Collaboration CVE-2015-6420 Cisco OpenVuln
Cisco Prime Central CVE-2015-6420 Cisco OpenVuln
Cisco Prime Access Registrar CVE-2015-6420 Cisco OpenVuln
Cisco NAC Appliance Software CVE-2015-6420 Cisco OpenVuln
Cisco Mobility Services Engine CVE-2015-6420 Cisco OpenVuln
Cisco MeetingPlace Server CVE-2015-6420 Cisco OpenVuln
Cisco MediaSense CVE-2015-6420 Cisco OpenVuln
Cisco Identity Services Engine Software CVE-2015-6420 Cisco OpenVuln
Cisco IP Interoperability and Collaboration System (IPICS) CVE-2015-6420 Cisco OpenVuln
Cisco Hosted Collaboration Mediation Fulfillment CVE-2015-6420 Cisco OpenVuln
Cisco Emergency Responder CVE-2015-6420 Cisco OpenVuln
Cisco Digital Media Manager Software CVE-2015-6420 Cisco OpenVuln
Cisco Data Center Analytics Framework CVE-2015-6420 Cisco OpenVuln
Cisco Cloupia Unified Infrastructure Controller CVE-2015-6420 Cisco OpenVuln
Cisco Cloud Services Platforms CVE-2015-6420 Cisco OpenVuln
Cisco Cloud Services Platform 2100 CVE-2015-6420 Cisco OpenVuln
Cisco Broadband Access Center Telco and Wireless CVE-2015-6420 Cisco OpenVuln
Cisco Broadband Access Center Telco Wireless Software CVE-2015-6420 Cisco OpenVuln
Cisco ASA CX Context-Aware Security Software CVE-2015-6420 Cisco OpenVuln