WebLogic - CVE-2019-2729
Oracle WebLogic server is affected by a remote code execution vulnerability in wls-wsat.war
and wls9_async_response.war
packages due to unsafe deserialization of Java objects. A remote unauthenticated attacker can exploit the issue by sending a custom Java serialized object via HTTP request to execute arbitrary Java code in the context of the web server.
Exploiting wls-wsat.war
will return command output, while wls9_async_response.war
is blind.
Affected versions: 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0
Vulnerable endpoints
Test data
10.3.6.0
Vulnerable
wls-wsat deserialization
12.2.1.3
Not vulnerable
Endpoints missing
12.2.1.3
Not vulnerable
Endpoints missing
12.2.1.3
Inconclusive
"Old format work area header is disabled."
Scripts
Last updated
Was this helpful?