CERT mailing list archives
Apache Commons Collections Java Library Vulnerability
From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 13 Nov 2015 15:11:13 -0600
NCCIC / US-CERT National Cyber Awareness System: Apache Commons Collections Java Library Vulnerability [ https://www.us-cert.gov/ncas/current-activity/2015/11/13/Apache-Commons-Collections-Java-Library-Vulnerability ] 11/13/2015 03:16 PM EST Original release date: November 13, 2015 US-CERT is aware of a deserialization vulnerability in the Apache Commons Collections (ACC) Java library. Java applications that either directly use ACC, or contain ACC in their classpath, may be vulnerable to arbitrary code execution. US-CERT encourages users and administrators to review Vulnerability Note VU#576313 [ http://www.kb.cert.org/vuls/id/576313 ] for more information and apply the necessary mitigations. ________________________________________________________________________ This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy & Use [ http://www.us-cert.gov/privacy/ ] policy. ________________________________________________________________________ A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () ncas us-cert gov to your address book. OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ http://www.us-cert.gov/related-resources ] STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ]
Current thread:
- Apache Commons Collections Java Library Vulnerability US-CERT (Nov 13)