WebLogic Anti-Serialization vulnerability test and resolution __ problem solving

Source: Internet
Author: User
Tags serialization

First, Test

Java-jar commonscollectionstools.jar WebLogic 192.168.0.11 7001 f:/a.txt

After performing this operation, if the computer on the IP generated a.txt file, proof of the existence of the vulnerability (This command for window operation, Linux to modify the file path, has not been tested).


Test jar Download Address: http://download.csdn.net/detail/gongzi2311/9434503


second, solve

1. Quick fix

Found it.. \weblogic\middleware\modules\com.bea.core.apache.commons.collections_3.2.0.jar and Open,

Find the Org\apache\commons\collections\functors\invokertransformer.class inside.

Then delete and save it. A new test found that the file could not be generated and the vulnerability was temporarily resolved.


2. Patch Solution

Download P20780171_1036_generic.zip, p22248372_1036012_generic.zip these two patch packs and install them.


Patch Package Download: http://pan.baidu.com/s/1i3Oy7Ox

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.