IBM WebSphere Remote Code Execution Java Deserialization

Discussion in 'News Aggregator' started by Packet Storm, 15 Mar 2017.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a vulnerability in IBM's WebSphere Application Server. An unsafe deserialization call of unauthenticated Java objects exists to the Apache Commons Collections (ACC) library, which allows remote arbitrary code execution. Authentication is not required in order to exploit this vulnerability.

    Continue reading...
     

Share This Page

Loading...