Demonstrating CVE-2020-4450: Getting Remote Code Execution on IBM WebSphere

Опубликовано: 21 Июль 2020
на канале: Zero Day Initiative
2,817
18

This video demonstrates how an unauthenticated attacker could execute commands on affected versions of the IBM WebSphere application server. A flaw exists within the handling of the IIOP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data.

For full details on the bug, see the blog published at:
https://www.zerodayinitiative.com/blo...