---
id: CVE-2015-6420
title: >-
  Serialized-object interfaces in certain Cisco Collaboration and Social Media;
  Endpoint Clients and Client Software; Network Application, Service, and
  Acceleration; Network and Content Security Devices; Network Management and
  Provisioning…
summary: >-
  Serialized-object interfaces in certain Cisco Collaboration and Social Media;
  Endpoint Clients and Client Software; Network Application, Service, and
  Acceleration; Network and Content Security Devices; Network Management and
  Provisioning…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: apache
product: commons_collections
affected:
  - 'commons_collections >= 3.0, < 3.2.2'
  - commons_collections = 4.0
patched:
  - commons_collections 3.2.2
published: '2015-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:07.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2015-6420'
references:
  - url: >-
      http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization
    label: psirt@cisco.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/78872'
    label: psirt@cisco.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
    label: psirt@cisco.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
    label: psirt@cisco.com
  - url: >-
      https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E
    label: psirt@cisco.com
  - url: 'https://www.kb.cert.org/vuls/id/581311'
    label: psirt@cisco.com
  - url: 'https://www.tenable.com/security/research/tra-2017-14'
    label: psirt@cisco.com
  - url: 'https://www.tenable.com/security/research/tra-2017-23'
    label: psirt@cisco.com
  - url: >-
      http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/78872'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://news.apache.org/foundation/entry/apache_commons_statement_to_widespread
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/576313'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/581311'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/research/tra-2017-14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/research/tra-2017-23'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T17:55:00.626377Z'
epss: 0.18763
epssPercentile: 0.97211
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Leeziao/CVE-2015-6420'
  checkedAt: '2026-10-07T18:42:55.476Z'
exploitAvailable: true
ingestedAt: '2026-10-07T18:42:20.869Z'
---

## Overview

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

## Affected

- `commons_collections >= 3.0, < 3.2.2`
- `commons_collections = 4.0`

## Remediation

Upgrade past the affected range:

- `commons_collections 3.2.2`
