The modification method is:
1.ExtractWebLogicUnder theModules/com.bea.core.apache.commons.collections_3.2.0.jar
2.Delete one of theInvokertransformer.classClass
3.Re-packagingCom.bea.core.apache.commons.collections_3.2.0.jar
4.Delete cache under domain, restart
Test strategy:
In the daily test environment forWebLogicThe anti-serialization security issue is fixed and tested for deployed system applications.
The first round of targeted testing, specifically for the core commonly used functional modules for functional testing.
The second round is a continuous test, and the week-long task test is tested on this environment as usual to see if it will be affected. And will always be tested as a test environment.
Test Results:
A part of the program was found during the testBug, it has not been discovered that the fix caused by the deserialization problemthe defect.
This article is from the "Sim blog," Please make sure to keep this source http://mitac.blog.51cto.com/1081911/1865264
Oracle WebLogic Server 10.3.2 Bug Fix method