module

WebLogic Server Deserialization RCE - BadAttributeValueExpException

Disclosed
Jan 15, 2020

Description

There exists a Java object deserialization vulnerability
in multiple versions of WebLogic.

Unauthenticated remote code execution can be achieved
by sending a serialized BadAttributeValueExpException object
over the T3 protocol to vulnerable WebLogic servers.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.