Researchers warn of unpatched vulnerability in Oracle WebLogic Server

Several security companies have detected scans over the past week that look for Oracle WebLogic servers vulnerable to a flaw that hasn’t yet been patched, possibly in preparation for malicious attacks. The vulnerability is a deserialization bug that can lead to remote code execution, but it’s located in a specific package called wls9_async_response that’s not included by default in all WebLogic server builds.

Read full article on CSO

 


Date:

Categorie(s):