VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2015-6420

⇱ NVD - CVE-2015-6420


  1. Vulnerabilities

CVE-2015-6420 Detail

Description

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.


Metrics

 
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization CVE, Cisco Systems, Inc. Third Party Advisory 
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html CVE, Cisco Systems, Inc. Third Party Advisory 
http://www.securityfocus.com/bid/78872 CVE, Cisco Systems, Inc. Third Party Advisory  VDB Entry 
https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ CVE Exploit  Third Party Advisory 
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 CVE, Cisco Systems, Inc. Third Party Advisory 
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 CVE, Cisco Systems, Inc. Third Party Advisory 
https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E CVE, Cisco Systems, Inc. Vendor Advisory 
https://news.apache.org/foundation/entry/apache_commons_statement_to_widespread CVE Vendor Advisory 
https://www.kb.cert.org/vuls/id/576313 CVE Third Party Advisory 
https://www.kb.cert.org/vuls/id/581311 CVE, Cisco Systems, Inc. Third Party Advisory 
https://www.tenable.com/security/research/tra-2017-14 CVE, Cisco Systems, Inc. Third Party Advisory 
https://www.tenable.com/security/research/tra-2017-23 CVE, Cisco Systems, Inc. Third Party Advisory 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-502 Deserialization of Untrusted Data πŸ‘ cwe source acceptance level
NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

18 change records found show changes

CVE Modified by Cisco Systems, Inc. 6/16/2026 8:30:51 PM

Action Type Old Value New Value
Added Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]


Reanalysis by NIST 2/24/2026 2:36:10 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (excluding) 3.2.2


OR
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions from (including) 3.0 up to (excluding) 3.2.2


Modified Analysis by NIST 2/24/2026 2:21:36 PM

Action Type Old Value New Value
Added CVSS V3.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Changed CPE Configuration
OR
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (including) 3.2.1
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*


OR
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (excluding) 3.2.2


Added Reference Type
CVE: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Types: Third Party Advisory


Added Reference Type
CVE: https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ Types: Exploit, Third Party Advisory


Added Reference Type
CVE: https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E Types: Vendor Advisory


Added Reference Type
CVE: https://news.apache.org/foundation/entry/apache_commons_statement_to_widespread Types: Vendor Advisory


Added Reference Type
CVE: https://www.kb.cert.org/vuls/id/576313 Types: Third Party Advisory


Added Reference Type
CVE: https://www.kb.cert.org/vuls/id/581311 Types: Third Party Advisory


Added Reference Type
Cisco Systems, Inc.: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Types: Third Party Advisory


Added Reference Type
Cisco Systems, Inc.: https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E Types: Vendor Advisory


Added Reference Type
Cisco Systems, Inc.: https://www.kb.cert.org/vuls/id/581311 Types: Third Party Advisory


CVE Modified by CVE 3/25/2025 1:15:41 PM

Action Type Old Value New Value
Added Reference
https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/


Added Reference
https://news.apache.org/foundation/entry/apache_commons_statement_to_widespread


Added Reference
https://www.kb.cert.org/vuls/id/576313


CVE Modified by CVE 11/20/2024 9:34:57 PM

Action Type Old Value New Value
Added Reference
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization


Added Reference
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html


Added Reference
http://www.securityfocus.com/bid/78872


Added Reference
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917


Added Reference
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722


Added Reference
https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E


Added Reference
https://www.kb.cert.org/vuls/id/581311


Added Reference
https://www.tenable.com/security/research/tra-2017-14


Added Reference
https://www.tenable.com/security/research/tra-2017-23


CVE Modified by Cisco Systems, Inc. 5/13/2024 11:39:55 PM

Action Type Old Value New Value

CVE Modified by Cisco Systems, Inc. 11/06/2023 9:26:50 PM

Action Type Old Value New Value
Added Reference
Cisco Systems, Inc. https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E [No types assigned]


Removed Reference
Cisco Systems, Inc. https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21@%3Ccommits.samza.apache.org%3E


CVE Modified by Cisco Systems, Inc. 3/10/2021 11:15:13 AM

Action Type Old Value New Value
Added Reference
https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21@%3Ccommits.samza.apache.org%3E [No Types Assigned]


Removed Reference
https://www.kb.cert.org/vuls/id/576313 [Third Party Advisory]


CVE Modified by Cisco Systems, Inc. 10/01/2018 5:29:00 PM

Action Type Old Value New Value
Added Reference
https://www.kb.cert.org/vuls/id/581311 [No Types Assigned]


CVE Modified by Cisco Systems, Inc. 7/18/2018 9:29:02 PM

Action Type Old Value New Value
Added Reference
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html [No Types Assigned]


Modified Analysis by NIST 12/14/2017 1:30:21 PM

Action Type Old Value New Value
Added CWE
CWE-502


Removed CWE
NVD-CWE-Other


Changed CPE Configuration
OR
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (including) 3.2.1
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (including) 4.0


OR
 *cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:* versions up to (including) 3.2.1
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*


Added Reference
https://www.kb.cert.org/vuls/id/576313 [Third Party Advisory]


Changed Reference Type
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization No Types Assigned


http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization Third Party Advisory


Changed Reference Type
http://www.securityfocus.com/bid/78872 No Types Assigned


http://www.securityfocus.com/bid/78872 Third Party Advisory, VDB Entry


Changed Reference Type
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 No Types Assigned


https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 Third Party Advisory


Changed Reference Type
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 No Types Assigned


https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory


Changed Reference Type
https://www.tenable.com/security/research/tra-2017-14 No Types Assigned


https://www.tenable.com/security/research/tra-2017-14 Third Party Advisory


Changed Reference Type
https://www.tenable.com/security/research/tra-2017-23 No Types Assigned


https://www.tenable.com/security/research/tra-2017-23 Third Party Advisory


Removed Evaluator Description
<a href="http://cwe.mitre.org/data/definitions/502.html">CWE-502: Deserialization of Untrusted Data</a>


CVE Modified by Cisco Systems, Inc. 11/07/2017 9:29:02 PM

Action Type Old Value New Value
Added Reference
https://www.tenable.com/security/research/tra-2017-23 [No Types Assigned]


CVE Modified by Cisco Systems, Inc. 11/02/2017 9:29:01 PM

Action Type Old Value New Value
Added Reference
https://www.tenable.com/security/research/tra-2017-14 [No Types Assigned]


CVE Modified by Cisco Systems, Inc. 2/16/2017 9:59:04 PM

Action Type Old Value New Value
Added Reference
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 [No Types Assigned]


CVE Modified by Cisco Systems, Inc. 1/19/2017 9:59:03 PM

Action Type Old Value New Value
Added Reference
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 [No Types Assigned]


CVE Modified by Cisco Systems, Inc. 11/28/2016 2:39:17 PM

Action Type Old Value New Value
Added Reference
http://www.securityfocus.com/bid/78872 [No Types Assigned]


Modified Analysis by NIST 12/15/2015 10:47:52 PM

Action Type Old Value New Value
Added CVSS V2
(AV:N/AC:L/Au:N/C:P/I:P/A:P)


Added CWE
NVD-CWE-Other


Added CPE Configuration
Configuration 1
 OR
 *cpe:2.3:a:apache:commons_collections:3.2.1:*:*:*:*:*:*:* (and previous)
 *cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:* (and previous)


Added Evaluator Description
<a href="http://cwe.mitre.org/data/definitions/502.html">CWE-502: Deserialization of Untrusted Data</a>


Initial CVE Analysis 12/15/2015 10:52:51 AM

Action Type Old Value New Value

Quick Info

CVE Dictionary Entry:
CVE-2015-6420
NVD Published Date:
12/15/2015
NVD Last Modified:
06/16/2026
Source:
Cisco Systems, Inc.