Other nomination
Java Deserialization w/ Apache Commons Collections in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS
Apache Commons Collections contains a gadget chain whose readObject ends in an arbitrary command execution, so any Java service that deserializes attacker-supplied data is pre-authentication remote code execution. The post shows how to recognise serialized objects on the wire and gives working exploits for WebSphere, JBoss, Jenkins, WebLogic and OpenNMS.
Record
- Researcher
- Stephen Breen
- Date
In the archive
Related sources
- Original disclosure slides
- Detailed explanation talk
- Original researchers’ payload generator
- Exploit source code
Tags
This page is the archive's own catalogue record. The research is the work of Stephen Breen, first published at the original source. Preserved copies are kept so the citation survives its host.