Vulnerability CVE-2015-6420 - AWI commons-collections.jar files

book

Article ID: 223586

calendar_today

Updated On:

Products

CA Automic One Automation

Issue/Introduction

The following vulnerability was found with the AWI and commons-collections.jar vulnerabilities:

CVE-2015-6420 - https://nvd.nist.gov/vuln/detail/CVE-2015-6420 - automic.sso.jar:lib/commons-collections.jar, org.eclipse.osgi/xx/x/.cp/lib/commons-collections.jar

Cause

High risk/impact vulnerability with 3rd party .jar file

Environment

Release : 12.3

Component : AUTOMATION ENGINE

Resolution

This will be resolved in a future release of 12.3 and version 21.  It will be resolved by using an upgraded version of commons-collections.jar.jar