WebLogic Server Deserialization Remote Code Execution
Posted by deepcore on May 25, 2020 – 3:31 pm
This Metasploit module exploits a Java object deserialization vulnerability in multiple versions of WebLogic. Unauthenticated remote code execution can be achieved by sending a serialized BadAttributeValueExpException object over the T3 protocol to vulnerable WebLogic servers.
Post a reply
You must be logged in to post a comment.