This video demonstrates how an unauthenticated attacker could execute commands on affected versions of the IBM WebSphere application server. A flaw exists within the handling of the IIOP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data.
For full details on the bug, see the blog published at:
https://www.zerodayinitiative.com/blo...