Kaspersky ID:
KLA10705
Detect Date:
11/19/2015
Updated:
06/03/2020

Description

Successful exploitation of the identified vulnerabilities may allow an attacker to execute arbitrary code and commands.

  1. Unknown vulnerability at Ice Faces servlet allows remote attackers to upload and execute arbitrary Java code via a specially designed XML document;
  2. Unknown vulnerability allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.

Original advisories

Related products

CVE list

  • CVE-2015-7912
    critical
  • CVE-2015-7913
    high

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.