Demonstrating CVE-2020-2883 Version 1: Remote Code Execution in Oracle's WebLogic Server

Опубликовано: 11 Май 2020
на канале: Trend Zero Day Initiative
2,703
11

This video demonstrates how an unauthenticated attacker could execute commands on affected Oracle WebLogic Servers. We use a gadget chain constructed with the ExtractorComparator class to embed a specially crafted object in the T3 protocol.

For full details on the vulnerability, see the blog at https://www.zerodayinitiative.com/blo...