← Back

CVE-2015-3253

nvd nist
Published: Aug 13, 2015Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

Affected (120)

1 product
Groovy
5 products
Retail Order Broker Cloud Service
Retail Service Backbone
Retail Store Inventory Management
Webcenter Sites
Configuration A
103 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 1.7.0
Version 1.7.0 beta_1
Version 1.7.0 beta_2
Version 1.7.0 rc1
Version 1.7.0 rc2
Version 1.7.10
Version 1.7.11
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.7.8
Version 1.7.9
Version 1.8.0
Version 1.8.0 beta_1
Version 1.8.0 beta_2
Version 1.8.0 beta_3
Version 1.8.0 beta_4
Version 1.8.0 rc1
Version 1.8.0 rc2
Version 1.8.0 rc3
Version 1.8.0 rc4
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.8.9
Version 1.9.0
Version 1.9.0 beta_1
Version 1.9.0 beta_3
Version 1.9.0 beta_4
Version 2.0.0
Version 2.0.0 beta_1
Version 2.0.0 beta_2
Version 2.0.0 beta_3
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.0 rc4
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.1.0
Version 2.1.0 beta_1
Version 2.1.0 rc1
Version 2.1.0 rc2
Version 2.1.0 rc3
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1.8
Version 2.1.9
Version 2.2.0
Version 2.2.0 beta_1
Version 2.2.0 beta_2
Version 2.2.0 rc1
Version 2.2.0 rc2
Version 2.2.0 rc3
Version 2.2.1
Version 2.2.2
Version 2.3.0
Version 2.3.0 beta_1
Version 2.3.0 beta_2
Version 2.3.0 rc1
Version 2.3.0 rc2
Version 2.3.0 rc3
Version 2.3.10
Version 2.3.11
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.0
Version 2.4.0 beta_1
Version 2.4.0 beta_2
Version 2.4.0 beta_3
Version 2.4.0 beta_4
Version 2.4.0 rc1
Version 2.4.0 rc2
Version 2.4.1
Version 2.4.2
Version 2.4.3
Configuration B
15 vulnerable
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 11.1.1.8.0
Version 12.2.1

References (46)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
MitigationThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.