This video demonstrates how an unauthenticated attacker could execute commands on affected Oracle WebLogic Servers. The vulnerability results from an insecure deserialization bug in the Oracle Coherence library. Oracle patched this in January 2020 and assigned it CVE-2020-2555.