This video demonstrates a code execution bug in the IBM WebSphere deployment manager. The specific flaw exists within the BroadcastMessageManager class. The issue results from the lack of proper validation of user-supplied data, which can result in the deserialization of untrusted data.
For full details on the bug used in this video, read the blog at:
https://www.zerodayinitiative.com/blo...