Back to Database
Status published
Critical
CVE-2015-3253
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through...
Vulnerability Description
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-3253
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- https://access.redhat.com/errata/RHSA-2017:2596
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- https://access.redhat.com/errata/RHSA-2016:1376
- https://security.gentoo.org/glsa/201610-01
- http://groovy-lang.org/security.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
- http://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.html
- https://security.netapp.com/advisory/ntap-20160623-0001/
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://rhn.redhat.com/errata/RHSA-2016-0066.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
- http://www.securityfocus.com/bid/91787
- http://www.zerodayinitiative.com/advisories/ZDI-15-365/
- https://access.redhat.com/errata/RHSA-2017:2486
- http://www.securitytracker.com/id/1034815
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.securityfocus.com/bid/75919
- http://www.securityfocus.com/archive/1/536012/100/0/threaded
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardingsphere.apache.org%3E
More from apache
View All →CVE-2025-58712
Amq: privilege escalation via excessive /etc/passwd permissions
Medium
6.4
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Medium
6.5
CVE-2021-24117
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability...
Medium
4.9
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID...
Critical
9.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3...
High
7.8
Affected Vendor
apache
View all reports →Affected Software
groovy, health sciences clinical development center, retail order broker cloud service, retail service backbone, retail store inventory management, webcenter sites
Vulnerable Versions:
1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.7.8, 1.7.9, 1.7.10, 1.7.11, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6, 1.8.7, 1.8.8, 1.8.9, 1.9.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 2.3.11, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 3.1.1, 3.1.2, 4.1, 5.1, 5.2, 15.0, 13.0, 13.1, 13.2, 14.0, 14.1, 11.1.1.8.0, 12.2.1
Timeline
Official Publish:
August 13th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.