Demonstrating CVE-2020-2883 Version 2: Remote Code Execution in Oracle's WebLogic Server

Опубликовано: 11 Май 2020
на канале: Zero Day Initiative
1,083
10

This video demonstrates how an unauthenticated attacker could execute commands on affected Oracle WebLogic Servers. We use a gadget chain constructed with the AbstractExtractor class to embed a specially crafted object in the T3 protocol.

For full details on the vulnerability, see the blog at https://www.zerodayinitiative.com/blo...