CERT mailing list archives

Apache Commons Collections Java Library Vulnerability


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 13 Nov 2015 15:11:13 -0600

NCCIC / US-CERT

National Cyber Awareness System:

Apache Commons Collections Java Library Vulnerability [ 
https://www.us-cert.gov/ncas/current-activity/2015/11/13/Apache-Commons-Collections-Java-Library-Vulnerability ] 
11/13/2015 03:16 PM EST 
Original release date: November 13, 2015

US-CERT is aware of a deserialization vulnerability in the Apache Commons Collections (ACC) Java library. Java 
applications that either directly use ACC, or contain ACC in their classpath, may be vulnerable to arbitrary code 
execution.

US-CERT encourages users and administrators to review Vulnerability Note VU#576313 [ 
http://www.kb.cert.org/vuls/id/576313 ] for more information and apply the necessary mitigations.

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ] 

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: