Home / os / winnt

WebLogic Server Deserialization Remote Code Execution

Posted on 21 May 2020

This Metasploit module exploits a Java object deserialization vulnerability in multiple versions of WebLogic. Unauthenticated remote code execution can be achieved by sending a serialized BadAttributeValueExpException object over the T3 protocol to vulnerable WebLogic servers.

 

TOP